PraetorixGRC · NIS2 · ZKB ← Back to the main page
GDPR

GDPR Compliance Statement

A statement on how we meet the obligations of Regulation (EU) 2016/679 in providing the Praetorix and Vigil services. Written for clients, procurement teams and their auditors assessing us as a processor.

Effective from 13 August 2026 · version 1.0

1. Purpose and scope

This statement describes how we meet our obligations under Regulation (EU) 2016/679 (GDPR) and Slovak Act No. 18/2018 Coll. on personal data protection when providing the Praetorix service (a cybersecurity governance system for NIS2 and Slovak Act No. 69/2018 Coll.), Vigil (security monitoring and tamper-evident audit records) and related security and advisory services, including acting as a cybersecurity manager.

It is written for clients, procurement teams and their auditors assessing us as a processor before a contract is signed. It does not replace the data processing agreement — that is concluded separately for each deployment and prevails in the event of any conflict.

Processing of personal data of visitors to this website is governed by our Privacy Policy; this statement concerns the operation of services for a client.

2. The provider

Marina Industries s. r. o.
Registered office: Osvienčimská 1718/10, 911 01 Trenčín, Slovak Republic
Company ID: 55740561, Tax ID: 2122086554, registered with the Commercial Register of the District Court Trenčín, Section Sro, Insert No. 45805/R
E-mail: office@marinaindustries.pro
Phone: +421 903 667 654
Contact person for data protection matters: Branislav Anwarzai

We are not required to designate a data protection officer under Article 37 GDPR. Data protection matters are handled by the contact person named above; where a client requires communication with a designated officer on its side, we commit to that in the contract.

3. Roles of the parties

When providing our services we process personal data as a processor within the meaning of Article 28 GDPR. The client remains the controller — it determines the purposes and means of processing and is responsible for the legal basis. We process the data solely on the client's documented instructions and never for our own purposes; in particular not for product development, model training, cross-client statistics or marketing.

If we consider an instruction to infringe the GDPR or another data protection provision, we inform the client immediately and suspend the processing concerned until the matter is resolved.

In our own capacity as a controller we process only the data needed to run our business: contact details of the client's representatives, billing data, records of communication and access logs to our systems. The legal bases are performance of a contract, compliance with legal obligations and our legitimate interest in security and accountability.

4. Data processing agreement

Before any processing begins we conclude a written data processing agreement containing all the elements of Article 28(3) GDPR — the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects, and the rights and obligations of the controller. The agreement binds us in particular to:

  • process personal data only on documented instructions, including as regards transfers to third countries;
  • ensure that persons authorised to process the data are bound by a written confidentiality obligation that survives the end of our cooperation;
  • implement and maintain the measures required by Article 32 GDPR;
  • engage sub-processors only under the conditions of Article 28(2) and (4);
  • assist with data subject rights and with the obligations under Articles 32 to 36;
  • at the end of the engagement, delete or return the personal data at the client's choice;
  • make available the information needed to demonstrate compliance and allow audits, including inspections.

5. Processing principles

We govern processing by the principles of Article 5 GDPR:

  • Data minimisation. Only data needed for the agreed purpose enters the system; the scope is set by the contract and the deployment configuration, not by what is technically possible.
  • Purpose limitation. Data from one client's operation is never used for another client or for our own analytics.
  • Storage limitation. Retention periods are agreed in the contract and enforced technically; data is removed automatically once they expire.
  • Integrity and confidentiality. Client environments are segregated, access is role-based and recorded.
  • Accountability. We can demonstrate compliance through records — the audit trail, records of processing activities and documented measures.

6. Categories of data and data subjects

The exact scope is set by the contract; typically it covers:

ServiceTypical categories of personal dataData subjects
Praetorix (GRC)name, job role, work e-mail and phone, records of tasks, approvals and trainingthe client's employees and contractors holding security roles
Vigil (monitoring, audit records)technical identifiers — user name, IP address, device identifier — and event metadata (time, type, outcome)users and administrators of the client's systems, and where applicable visitors to its services
Support and ticketsname, e-mail, phone, content of the requestthe client's contact persons

We do not process special categories of data under Article 9 GDPR or criminal conviction data under Article 10 as part of the services. Should a client enter such data into the system, this is possible only under a written agreement and with additional safeguards.

7. Data location and international transfers

We process data on infrastructure located in the European Union. In an on-premise deployment the entire solution runs inside the client's own infrastructure and the data never leaves it; our support accesses it only at the client's request, over a secured channel and with an audit record.

We do not transfer personal data to third countries outside the European Economic Area. Should this become necessary for a specific engagement, we will do so only after informing the client and on the basis of appropriate safeguards under Article 46 GDPR (in particular standard contractual clauses), together with a transfer impact assessment.

8. Technical and organisational measures (Article 32)

8.1 Protection of the data

  • encryption in transit (TLS) and encryption at rest;
  • pseudonymisation of identities in events using a key held separately for each client (HMAC);
  • crypto-shredding — destroying a client's key renders the data permanently unreadable, including copies in backups;
  • segregation of each client's environment and data.

8.2 Access control

  • role-based access control (RBAC) and least privilege, with periodic access reviews;
  • multi-factor authentication for administrative access;
  • named individual accounts with no shared credentials; administrative rights limited to what is necessary;
  • every administrative access is recorded and traceable.

8.3 Accountability and resilience

  • a tamper-evident audit trail (hash chaining with periodic anchoring) — any alteration or removal of an event is demonstrable;
  • backups with regularly tested restores and defined RPO/RTO;
  • vulnerability and patch management; separated development and production environments;
  • availability and security event monitoring with a documented incident response procedure;
  • regular testing of the effectiveness of the measures, with results recorded.

8.4 People and suppliers

  • written confidentiality undertakings from everyone with access to the data, surviving the end of the engagement;
  • instruction and regular training on data protection and security;
  • physical security is provided by our suppliers' data centres in the EU; workstations with access to client data are encrypted.

9. Sub-processors

We engage a sub-processor only on the basis of the client's prior general written authorisation, and we always impose on it the same data protection obligations that apply to us; we remain fully liable to the client for its performance. We give reasonable prior notice of any intended addition or replacement so that the client can object. The current list of sub-processors is available on request at the contact address above.

10. Data subject rights and assistance

Requests from data subjects are handled by the controller. Where a request concerns data processed in our services, we assist the client by appropriate technical and organisational measures with the rights of access, rectification, erasure, restriction, portability and objection (Articles 12 to 23 GDPR), without undue delay and normally within 5 working days of receiving the request, so that the controller can meet its one-month deadline. If a data subject contacts us directly, we forward the request to the controller without delay and do not answer it on the merits ourselves.

11. Records, audits and demonstrating compliance

We maintain records of categories of processing activities under Article 30(2) GDPR and make them available on request to the client or a supervisory authority. We make available to the client the information needed to demonstrate compliance with Article 28 and allow audits, including inspections conducted by the client or an auditor it mandates, at a time agreed in advance and with due regard to the confidentiality of other clients' data and to operational security.

12. Personal data breaches

We notify the client of a personal data breach without undue delay and normally within 24 hours of becoming aware of it, together with the known scope, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed, so that the client can meet the 72-hour deadline under Article 33 GDPR and assess communication to data subjects under Article 34. We provide the evidence from the audit trail needed for the investigation.

Where the same event is also an incident under the NIS2 Directive and Slovak Act No. 69/2018 Coll., we follow the 24-hour (early warning), 72-hour (incident notification) and one-month (final report) deadlines.

13. Impact assessments and prior consultation

At the client's request we assist with a data protection impact assessment under Article 35 GDPR and with prior consultation of the supervisory authority under Article 36 — in particular by describing the processing operations, the Article 32 measures and the data flows, to the extent available to a processor.

14. Data protection by design and by default (Article 25)

New functionality is designed with data protection built in: pseudonymised identities in events, segregated environments, the strictest permissions preset by default, retention enforced technically, and an audit record of every access to the data. The default configuration is always the one that processes the least data; widening the scope is a deliberate decision of the client.

15. End of the engagement

When the provision of services ends, we delete or return all personal data at the client's choice in an agreed format and destroy existing copies, unless retention is required by law. Copies held in backups expire with the agreed backup retention period; until then they remain protected by the same measures and are not accessible for any other purpose. We issue written confirmation of deletion on request.

16. Contact and supervisory authority

Questions about this statement, requests for the sub-processor list, for the data processing agreement or for audit evidence should be addressed to office@marinaindustries.pro.

Our supervisory authority is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava. A data subject has the right to lodge a complaint with the supervisory authority in the Member State of their habitual residence, place of work or place of the alleged infringement.

17. Validity and updates

This statement is effective from 13 August 2026, version 1.0. We update it whenever the scope of processing, the measures or the applicable law change; the current version is always available at this address with its effective date and version number.