This document explains what personal data Brand Force s.r.o. processes, why it processes it and what rights you have. It is divided by product type, because desktop applications, mobile applications, web applications, websites and web portals process different data and in different roles.
The controller is Brand Force s.r.o., registered office Gunduličova 899/1, 811 05 Bratislava, Slovak Republic, Company ID 52415325, Tax ID 2121044783, VAT ID SK2121044783, registered in the Commercial Register of the Municipal Court Bratislava III.
Branch: 17. novembra 2, 914 51 Trenčianske Teplice
Data protection e-mail: info@brandforce.sk
General contact: info@brandforce.sk, +421 911 911 400
We are not legally required to appoint a Data Protection Officer under Art. 37 GDPR and have not appointed one. Data protection matters are handled by company management at the e-mail address above.
This is the most important part of this document. Under the GDPR we act in two distinct roles, and this determines who you should contact to exercise your rights.
We are the controller for data we process for ourselves: visits to our own websites, contact forms, enquiries, commercial and contractual records of our customers and suppliers, and job applicants. In these cases you exercise your rights directly with us.
For data held in the information systems we operate for our customers (municipalities, public undertakings and companies), we act as a processor. The controller is our customer — for example the employer who granted you access, or the municipality maintaining the records. We handle such data solely on their documented instructions, under a data processing agreement pursuant to Art. 28 GDPR.
In practice: if you are an employee, citizen or client and want to know what data about you is held in a system, contact the organisation that granted you access or that maintains the records. We may not handle such a request on their behalf, but we will give them full assistance. If you are unsure who that is, write to us and we will point you in the right direction.
This covers native Windows and Linux applications we supply to our customers (for example IS DOBSCHAU, municipal IS, VOLMET, Movira). They are work tools — you sign in with credentials issued by your employer or the system operator. For the content you work with in them, we act as a processor as described in section 2.
Where the application supports signing documents with an eID card or another qualified device, the entire signing operation runs locally on your computer via the card reader and the PKCS#11 interface. You enter the PIN directly into the card driver and it never leaves your device — it is not sent to us and we do not store it. Only the resulting signed document is sent to the server; it contains your signing certificate, which is inherently part of the signature.
Desktop applications contain no analytics, advertising or behavioural tracking. We do not measure which features you use, how long you work, or when you launch the application.
This covers our Android applications for field staff (for example DOBSCHAU Zamestnanci). They are corporate applications — your account is created by your employer, who is also the data controller. We distribute them through Managed Google Play as a private application, or directly from our own update channel; they are not published in the public store. We do not publish an iOS application.
| Category | Specific data | When collected |
|---|---|---|
| Identity and sign-in | e-mail, password, optionally a two-factor code; alternatively sign-in by scanning a QR code from a computer | at sign-in |
| Location | device geographic coordinates | only during a specific action — submitting a job photo, recording arrival / break / transfer, a help request (SOS), or reporting a vehicle fault or route change. Never in the background and never continuously. If you decline the permission, the application keeps working and no location is sent. |
| Photographs | photos of the state before work, after work and at an incident; photo of a cash receipt | when you take the photo yourself. The application has no access to your gallery — it does not request media read permission and works only with images captured within it through the system camera. |
| Work records | timesheets (date, hours, description, issues), arrival, break and transfer times, dispatch messages, help requests, vehicle logbook and odometer readings | when you enter them |
| Device | phone manufacturer and model, application version, Android version and a randomly generated channel identifier for delivering notifications | when notifications are enabled — so dispatch knows which device to deliver an alert to |
Your application account is created and closed by your employer, who is the controller. Requests to close an account and delete data should therefore be addressed to them; as processor we will delete the data on their instruction. You may also send the request to us at info@brandforce.sk — we will forward it to the controller without delay and let you know. You can uninstall the application at any time, which removes all data stored on the device.
This covers information systems accessible in a browser after signing in (for example municipal and corporate IS, Movira, WiseLogic, VOLMET, internal systems). They are work tools for authorised users. For the content they hold we act as a processor — the controller is the organisation using the system.
Web applications use strictly necessary technical cookies only. Signing in and maintaining a secure session is impossible without them, so no consent is required under Art. 5(3) of the ePrivacy Directive. We use no analytics or marketing cookies.
| Cookie | Purpose | Attributes and lifetime |
|---|---|---|
dobsina_token | access token of the signed-in session in the municipal and corporate IS | HttpOnly, Secure, SameSite=Lax; approximately 30 minutes |
refresh_token | extends the session without re-entering your password | HttpOnly, Secure, SameSite=Lax, restricted to the auth endpoint; days |
session_hint | a flag with the value “1” telling the interface whether to attempt session restore; contains no information about you | Secure, SameSite=Lax; same lifetime as the refresh token |
bf_session | session in internal systems (BF IS, ALDECO) | HttpOnly, Secure, SameSite=Lax; 2 hours |
bf_csrf_cookie | protection against cross-site request forgery | HttpOnly, Secure, SameSite=Strict; 2 hours |
bf_theme_pref | remembers the light or dark appearance; contains no personal data | Secure, SameSite=Lax; 1 year |
In browser local storage some applications keep the sign-in token and your display preferences — sidebar collapse, table density, language, appearance. Signing out removes this data.
Where an application displays a map, map tiles are loaded through our server, not directly from the map service. This means your IP address never reaches the map data provider (OpenStreetMap, or ZBGIS operated by the Slovak Geodesy, Cartography and Cadastre Authority). We do not use Google Maps.
This covers the public presentation websites we operate (brandforce.sk and the sites of our brands and projects). Here we act as the controller.
If you write to us through a form, we process your name, e-mail, optionally a phone number, and the message content. The legal basis is our legitimate interest in answering your enquiry and establishing a business relationship (Art. 6(1)(f) GDPR); if a contract results, the basis becomes its performance (Art. 6(1)(b) GDPR). We keep the message for no more than 12 months from the last communication, or in line with accounting and tax rules if a business relationship arises. The message is also delivered to our mailbox.
Along with the message we record the sender's IP address and browser identifier to protect the form against abuse and bulk submissions. On brandforce.sk the IP address is not stored in readable form but only as an irreversible fingerprint; on our other sites it is currently stored directly and we are harmonising this. The legal basis is our legitimate interest in security (Art. 6(1)(f) GDPR).
On one of our sites (wiselogic.cz) fonts and icons are still loaded from the external Google Fonts and Cloudflare networks, which exposes your IP address and browser details to them. We are removing this dependency by moving the files to our own server; until then we disclose it openly here.
By portal we mean the sign-in area for customers and business partners — where you view documents, price lists, orders or documentation relating to your relationship with the portal operator (for example client zones and partner portals).
Every connection to our servers is recorded in the web server log: IP address, time, requested address, status code and browser identifier. This serves security and troubleshooting purposes (legitimate interest under Art. 6(1)(f) GDPR). We keep these logs for 14 days, after which they are deleted automatically.
We operate our own server infrastructure located in the European Union. We do not use public cloud platforms to store customer data. Backups are encrypted.
We do not sell personal data, do not share it with advertising networks or data brokers, and do not use it for automated decision-making with legal effect or for profiling. We do not transfer data outside the EEA except as stated above.
Under the GDPR you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand.
Send your request to info@brandforce.sk. We will respond within one month; for complex or repeated requests this may be extended by two months, of which we will inform you. There is no charge. If the request concerns a system we operate for a customer, we will forward it to them as controller without delay and let you know — see section 2.
If you believe our processing of your data infringes the law, you may lodge a complaint with a supervisory authority. Our competent authority is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk. You may also complain to the supervisory authority in the Member State of your habitual residence or place of work.
Our products are business and work tools. They are not directed at children and we do not knowingly process data of persons under 16. If we learn that we have obtained such data without the necessary legal basis, we will delete it.
We may update this policy when our products or the law change. The current version is always published at this address together with its version number and effective date. For material changes affecting your rights we will also notify users directly within the products concerned.