Brand Force s.r.o.

Privacy Policy

This document explains what personal data Brand Force s.r.o. processes, why it processes it and what rights you have. It is divided by product type, because desktop applications, mobile applications, web applications, websites and web portals process different data and in different roles.

Effective from: 2026-08-07 Version 1.1 Slovenčina Čeština English Deutsch Magyar Українська Polski

1. Who we are

The controller is Brand Force s.r.o., registered office Gunduličova 899/1, 811 05 Bratislava, Slovak Republic, Company ID 52415325, Tax ID 2121044783, VAT ID SK2121044783, registered in the Commercial Register of the Municipal Court Bratislava III.

Branch: 17. novembra 2, 914 51 Trenčianske Teplice
Data protection e-mail: info@brandforce.sk
General contact: info@brandforce.sk, +421 911 911 400

We are not legally required to appoint a Data Protection Officer under Art. 37 GDPR and have not appointed one. Data protection matters are handled by company management at the e-mail address above.

2. In what role we act

This is the most important part of this document. Under the GDPR we act in two distinct roles, and this determines who you should contact to exercise your rights.

Controller (we determine purpose and means)

We are the controller for data we process for ourselves: visits to our own websites, contact forms, enquiries, commercial and contractual records of our customers and suppliers, and job applicants. In these cases you exercise your rights directly with us.

Processor (we process on the customer's instructions)

For data held in the information systems we operate for our customers (municipalities, public undertakings and companies), we act as a processor. The controller is our customer — for example the employer who granted you access, or the municipality maintaining the records. We handle such data solely on their documented instructions, under a data processing agreement pursuant to Art. 28 GDPR.

In practice: if you are an employee, citizen or client and want to know what data about you is held in a system, contact the organisation that granted you access or that maintains the records. We may not handle such a request on their behalf, but we will give them full assistance. If you are unsure who that is, write to us and we will point you in the right direction.

3. Desktop applications

This covers native Windows and Linux applications we supply to our customers (for example IS DOBSCHAU, municipal IS, VOLMET, Movira). They are work tools — you sign in with credentials issued by your employer or the system operator. For the content you work with in them, we act as a processor as described in section 2.

What the application stores on your device

What the application sends

Qualified electronic signature

Where the application supports signing documents with an eID card or another qualified device, the entire signing operation runs locally on your computer via the card reader and the PKCS#11 interface. You enter the PIN directly into the card driver and it never leaves your device — it is not sent to us and we do not store it. Only the resulting signed document is sent to the server; it contains your signing certificate, which is inherently part of the signature.

Desktop applications contain no analytics, advertising or behavioural tracking. We do not measure which features you use, how long you work, or when you launch the application.

4. Mobile applications

This covers our Android applications for field staff (for example DOBSCHAU Zamestnanci). They are corporate applications — your account is created by your employer, who is also the data controller. We distribute them through Managed Google Play as a private application, or directly from our own update channel; they are not published in the public store. We do not publish an iOS application.

What data the application processes

CategorySpecific dataWhen collected
Identity and sign-ine-mail, password, optionally a two-factor code; alternatively sign-in by scanning a QR code from a computerat sign-in
Locationdevice geographic coordinatesonly during a specific action — submitting a job photo, recording arrival / break / transfer, a help request (SOS), or reporting a vehicle fault or route change. Never in the background and never continuously. If you decline the permission, the application keeps working and no location is sent.
Photographsphotos of the state before work, after work and at an incident; photo of a cash receiptwhen you take the photo yourself. The application has no access to your gallery — it does not request media read permission and works only with images captured within it through the system camera.
Work recordstimesheets (date, hours, description, issues), arrival, break and transfer times, dispatch messages, help requests, vehicle logbook and odometer readingswhen you enter them
Devicephone manufacturer and model, application version, Android version and a randomly generated channel identifier for delivering notificationswhen notifications are enabled — so dispatch knows which device to deliver an alert to

What the application does not do

Security on the device

Account and data deletion

Your application account is created and closed by your employer, who is the controller. Requests to close an account and delete data should therefore be addressed to them; as processor we will delete the data on their instruction. You may also send the request to us at info@brandforce.sk — we will forward it to the controller without delay and let you know. You can uninstall the application at any time, which removes all data stored on the device.

5. Web applications

This covers information systems accessible in a browser after signing in (for example municipal and corporate IS, Movira, WiseLogic, VOLMET, internal systems). They are work tools for authorised users. For the content they hold we act as a processor — the controller is the organisation using the system.

Cookies and local storage

Web applications use strictly necessary technical cookies only. Signing in and maintaining a secure session is impossible without them, so no consent is required under Art. 5(3) of the ePrivacy Directive. We use no analytics or marketing cookies.

CookiePurposeAttributes and lifetime
dobsina_tokenaccess token of the signed-in session in the municipal and corporate ISHttpOnly, Secure, SameSite=Lax; approximately 30 minutes
refresh_tokenextends the session without re-entering your passwordHttpOnly, Secure, SameSite=Lax, restricted to the auth endpoint; days
session_hinta flag with the value “1” telling the interface whether to attempt session restore; contains no information about youSecure, SameSite=Lax; same lifetime as the refresh token
bf_sessionsession in internal systems (BF IS, ALDECO)HttpOnly, Secure, SameSite=Lax; 2 hours
bf_csrf_cookieprotection against cross-site request forgeryHttpOnly, Secure, SameSite=Strict; 2 hours
bf_theme_prefremembers the light or dark appearance; contains no personal dataSecure, SameSite=Lax; 1 year

In browser local storage some applications keep the sign-in token and your display preferences — sidebar collapse, table density, language, appearance. Signing out removes this data.

Map data

Where an application displays a map, map tiles are loaded through our server, not directly from the map service. This means your IP address never reaches the map data provider (OpenStreetMap, or ZBGIS operated by the Slovak Geodesy, Cartography and Cadastre Authority). We do not use Google Maps.

6. Websites

This covers the public presentation websites we operate (brandforce.sk and the sites of our brands and projects). Here we act as the controller.

Contact form

If you write to us through a form, we process your name, e-mail, optionally a phone number, and the message content. The legal basis is our legitimate interest in answering your enquiry and establishing a business relationship (Art. 6(1)(f) GDPR); if a contract results, the basis becomes its performance (Art. 6(1)(b) GDPR). We keep the message for no more than 12 months from the last communication, or in line with accounting and tax rules if a business relationship arises. The message is also delivered to our mailbox.

Along with the message we record the sender's IP address and browser identifier to protect the form against abuse and bulk submissions. On brandforce.sk the IP address is not stored in readable form but only as an irreversible fingerprint; on our other sites it is currently stored directly and we are harmonising this. The legal basis is our legitimate interest in security (Art. 6(1)(f) GDPR).

Cookies and audience measurement

On one of our sites (wiselogic.cz) fonts and icons are still loaded from the external Google Fonts and Cloudflare networks, which exposes your IP address and browser details to them. We are removing this dependency by moving the files to our own server; until then we disclose it openly here.

7. Web portals

By portal we mean the sign-in area for customers and business partners — where you view documents, price lists, orders or documentation relating to your relationship with the portal operator (for example client zones and partner portals).

8. What applies to all products

Server logs

Every connection to our servers is recorded in the web server log: IP address, time, requested address, status code and browser identifier. This serves security and troubleshooting purposes (legitimate interest under Art. 6(1)(f) GDPR). We keep these logs for 14 days, after which they are deleted automatically.

Where your data is stored

We operate our own server infrastructure located in the European Union. We do not use public cloud platforms to store customer data. Backups are encrypted.

Recipients and sub-processors

We do not sell personal data, do not share it with advertising networks or data brokers, and do not use it for automated decision-making with legal effect or for profiling. We do not transfer data outside the EEA except as stated above.

Security

9. Your rights

Under the GDPR you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand.

Send your request to info@brandforce.sk. We will respond within one month; for complex or repeated requests this may be extended by two months, of which we will inform you. There is no charge. If the request concerns a system we operate for a customer, we will forward it to them as controller without delay and let you know — see section 2.

Supervisory authority

If you believe our processing of your data infringes the law, you may lodge a complaint with a supervisory authority. Our competent authority is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk. You may also complain to the supervisory authority in the Member State of your habitual residence or place of work.

10. Children

Our products are business and work tools. They are not directed at children and we do not knowingly process data of persons under 16. If we learn that we have obtained such data without the necessary legal basis, we will delete it.

11. Changes to this policy

We may update this policy when our products or the law change. The current version is always published at this address together with its version number and effective date. For material changes affecting your rights we will also notify users directly within the products concerned.