>
PraetorixGRC · NIS2 · ZKB ← Back to the main page
GDPR

Privacy Policy

Principles governing the processing of personal data of visitors to the praetorix.pro website, in accordance with Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll. on Personal Data Protection.

Effective from 13 August 2026 · version 1.2

1. Data controller

The data controller that determines the purposes and means of processing your personal data is:

Marina Industries s. r. o.
Registered office: Osvienčimská 1718/10, 911 01 Trenčín, Slovak Republic
Company ID (IČO): 55740561, registered in the Commercial Register of the District Court Trenčín, section Sro, file no. 45805/R
Email: office@marinaindustries.pro
Telephone: +421 903 667 654
Contact person for communication: Branislav Anwarzai

You may contact us using the details above in all matters relating to the processing of personal data and the exercise of your rights.

2. What personal data we process

We process personal data only to the extent necessary to achieve the intended purpose and only where you provide it to us yourself or where it arises during your visit to the website.

2.1 Data from the contact / request form (demo ticket)

If you submit a request for access or a demo via the form on the website, we process the data you enter in it, in particular:

  • identification and contact data — first name and surname, organisation name, job position, email address and, where applicable, telephone number;
  • data about the organisation and enquiry — sector of operation, classification under NIS2, size of the organisation, current status / tools used, target date, and any additional note.

2.2 Technical and access data

When you visit the website and pass through the security gate (verification that you are a human), we automatically process:

  • the IP address and information about your browser (the User-Agent header);
  • a technical security cookie phuman, which confirms successful verification and protects the website against automated access;
  • server access records (logs) and the date/time of the request.

Details about cookies can be found in the separate document Cookie Policy.

3. Purposes and legal bases for processing

Purpose of processingLegal basis (Article 6(1) GDPR)
Handling your request for access / a demo, communication, and preparation of a possible contract or offerpoint (b) — steps taken prior to entering into a contract at your request
Securing and protecting the website against automated misuse (security gate, logs)point (f) — the legitimate interest of the controller in the security and availability of the service
Compliance with legal obligations (e.g. accounting and archiving obligations, should a business relationship arise)point (c) — compliance with a legal obligation

Providing the data is voluntary; however, without the data from the form we are unable to handle your request. The technical and security data are necessary for the operation and protection of the website.

4. Recipients and processors

We do not disclose your personal data or provide it to third parties for marketing purposes. The data may be made available solely to:

  • providers of technical infrastructure (hosting, server operation), who act as processors on the basis of a contract and the controller's instructions;
  • the business partner / distributor of the Praetorix product, solely to the extent necessary to handle your specific request;
  • public authorities, where required by a specific legal regulation.

We do not transfer personal data to third countries outside the European Economic Area.

5. Retention period

  • Data from requests that do not lead to a business relationship is retained for a maximum of 12 months from the last communication, after which it is erased.
  • If a contractual relationship is concluded, the data is retained for its duration and for the period required by the applicable legal regulations (in particular accounting and tax regulations).
  • Security and server logs and the phuman cookie are retained for a short period — the cookie is valid for 2 hours, and logs are generally kept for up to 90 days.

6. Your rights

As a data subject, you have the following rights in connection with the processing of personal data:

  • the right of access to your personal data and to information about its processing;
  • the right to rectification of inaccurate data and completion of incomplete data;
  • the right to erasure ("the right to be forgotten") under the conditions set out in Article 17 GDPR;
  • the right to restriction of processing under Article 18 GDPR;
  • the right to data portability under Article 20 GDPR;
  • the right to object to processing based on a legitimate interest under Article 21 GDPR;
  • the right to lodge a complaint with the supervisory authority — the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, Slovakia.

You may exercise your rights by email at office@marinaindustries.pro. We will handle your request without undue delay, at the latest within one month.

7. Automated decision-making

We do not carry out automated individual decision-making or profiling with legal effects for data subjects. The security gate (the "I am human" verification) evaluates solely the technical characteristics of the access request and does not serve to profile individuals.

8. GDPR compliance statement for our services

The sections above concern visits to this website. This section describes the processing of personal data that takes place when we operate our services (Praetorix, Vigil and related security services) for a client.

8.1 Roles of the parties

When providing the services we act as a processor under Article 28 GDPR; the client is the controller and determines the purposes and means of processing. We process personal data solely on the client's documented instructions and never for our own purposes. A data processing agreement containing everything required by Article 28(3) — subject matter, duration, nature and purpose of processing, categories of personal data and data subjects, and the controller's rights and obligations — is part of onboarding and is concluded before any processing begins. Persons authorised to process the data are bound by confidentiality.

8.2 Data location and transfers to third countries

Data is processed on infrastructure located in the European Union. In an on-premise deployment the entire solution runs on the client's own infrastructure and the data never leaves it. We do not transfer personal data to third countries outside the European Economic Area; should this become necessary for a specific engagement, we will do so only after informing the client and with appropriate safeguards under Article 46 GDPR.

8.3 Technical and organisational measures (Article 32)

  • encryption in transit (TLS) and encryption of data at rest;
  • pseudonymisation of identities in events using a separate key per client (HMAC) and crypto-shredding — destroying the key renders the data unreadable;
  • separation of client environments and role-based access control (RBAC);
  • multi-factor authentication for administrative access and administrative privileges limited to what is necessary;
  • a tamper-evident audit log (hash chaining with periodic anchoring) that makes any alteration or removal of an event demonstrable;
  • backups with verified restoration, vulnerability and patch management, and regular testing of the effectiveness of the measures.

8.4 Sub-processors

We engage a sub-processor only on the basis of the client's prior general written authorisation and under the same data protection obligations as our own. Any change or addition to the list is notified in advance so that the client may object; the current list is provided on request.

8.5 Assistance, audits and personal data breaches

We assist the client in handling data subject requests, in carrying out a data protection impact assessment (Article 35) and in prior consultation with the supervisory authority (Article 36). We make available the information needed to demonstrate compliance and allow for audits, including inspections, under Article 28(3)(h). We maintain records of processing activities under Article 30(2) and produce them on request. A personal data breach is notified to the client without undue delay, as a rule within 24 hours of becoming aware of it, together with the known scope, the likely consequences and the measures taken, so that the client can meet the deadline under Article 33 GDPR. Where the event is also an incident under NIS2, we follow the 24-hour, 72-hour and one-month deadlines.

8.6 End of the engagement

When the provision of services ends we will, at the client's choice, delete or return all personal data and destroy existing copies, unless retention is required by law. Copies held in backups expire on the agreed backup retention period.

9. Measurement of traffic and advertising performance

We operate our own traffic measurement on this website. It tells us which parts of the pages visitors are interested in and which advertising campaign led to an enquiry. We run the measurement ourselves on our own infrastructure; we do not use third-party analytics services and we do not pass the measured data to them.

The measurement processes:

  • a visit identifier — a random number generated when the page loads, which exists solely in the browser's memory for the duration of a single visit and ceases to exist when the page is closed;
  • on-page events — page load, viewing the price list, clicking a call to action, starting and submitting the form, clicking a telephone number or e-mail address;
  • data on the source of the visit — the advertising click identifier (the gclid parameter) and the campaign label from the page address, if you arrived from an advertisement;
  • device type (mobile or desktop) and the address of the page visited;
  • an irreversible fingerprint of the IP address generated using HMAC-SHA256 with a secret key. We do not retain the IP address itself within the measurement and it cannot be recovered from the fingerprint; it serves solely to limit abuse.

The measurement stores nothing on your device — it uses no cookies, no browser local storage and no comparable technologies. It therefore does not require your consent under Section 109(8) of Act No. 452/2021 Coll. on Electronic Communications. The phuman security cookie referred to in Article 2.2 is unrelated to the measurement and serves a purely protective function.

Legal basis: legitimate interest under Article 6(1)(f) GDPR, namely assessing the functioning of the website and the effectiveness of our own promotion. You may object to this processing at any time under Article 21 GDPR at office@marinaindustries.pro.

Retention period: we retain the measured data for no more than 14 months from the time it arises, after which we delete it.

Transfer of enquiry data to the advertising system. If you arrived at the website from a search advertisement and submit the form, we may pass the advertising click identifier together with the time and value of the resulting enquiry to Google Ireland Limited in order to assess campaign effectiveness. We do not pass on your name, e-mail address, telephone number or the content of your message. Where this involves a transfer outside the European Economic Area, the standard contractual clauses under Article 46 GDPR apply.

10. Changes to this policy

We may update this policy in response to changes in legislation or in the scope of processing. The current version is always available on this page, together with the effective date.