General Data Protection Regulation (GDPR) Compliance
Last Updated: October 26, 2025
Polrex Uskan ("we," "us," or "our") is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). This policy explains how we collect, use, store, and protect your information when you use our online workshop platform and services.
1. Data Controller Information
The data controller responsible for your personal data is:
Polrex Uskan
M. R. Štefánika 54
036 01, Martin, Slovakia
Email: help@niknu-v2.com
Phone: +421908254383
2. Personal Data We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, password, phone number, profile information
- Payment Information: Billing address, payment method details (processed securely through third-party payment processors)
- Workshop Data: Assignments submitted, exercise responses, progress tracking, collaborative project contributions
- Communications: Messages sent through our platform, support inquiries, feedback submissions
- Profile Enhancements: Professional background, learning goals, skills assessments, optional demographic information
2.2 Information Collected Automatically
- Technical Data: IP address, browser type and version, device information, operating system
- Usage Data: Pages visited, time spent on platform, features accessed, workshop completion rates
- Cookies and Tracking: Session identifiers, preference settings, analytics data
- Performance Data: Error logs, system diagnostics, loading times
2.3 Information from Third Parties
- Social media profile data if you register using third-party authentication
- Payment verification from payment processors
- Marketing and analytics partners (with your consent)
3. Legal Basis for Processing
We process your personal data based on the following legal grounds:
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and management | Contract performance |
| Providing workshop services and content | Contract performance |
| Payment processing | Contract performance |
| Customer support | Contract performance and legitimate interest |
| Platform improvements and analytics | Legitimate interest |
| Marketing communications | Consent (can be withdrawn) |
| Legal compliance and fraud prevention | Legal obligation |
| Security and system integrity | Legitimate interest |
4. How We Use Your Personal Data
We use your personal data for the following purposes:
- Service Delivery: Provide access to workshops, assignments, interactive exercises, and collaborative tools
- Personalization: Customize learning experiences, recommend relevant content, track progress
- Communication: Send workshop updates, assignment notifications, technical announcements, customer support responses
- Payment Processing: Process transactions, issue invoices, manage subscriptions
- Platform Improvement: Analyze usage patterns, conduct research, develop new features
- Security: Detect and prevent fraud, protect against unauthorized access, maintain system integrity
- Legal Compliance: Fulfill legal obligations, respond to lawful requests, enforce our terms
- Marketing: Send promotional materials about new workshops and features (with your consent)
5. Data Sharing and Disclosure
We may share your personal data with the following categories of recipients:
5.1 Service Providers
- Cloud hosting and infrastructure providers
- Payment processors and financial institutions
- Email and communication service providers
- Analytics and monitoring tools
- Customer support platforms
- Content delivery networks
5.2 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred to the relevant third party.
5.3 Legal Requirements
We may disclose your data when required by law, court order, or governmental authority, or when necessary to protect our rights, property, or safety.
5.4 With Your Consent
We may share your data with third parties when you have provided explicit consent for such sharing.
Note: We do not sell your personal data to third parties for their marketing purposes.
6. International Data Transfers
Your personal data may be transferred to and processed in countries outside your country of residence, including countries that may not provide the same level of data protection as your home country.
When we transfer data internationally, we implement appropriate safeguards, including:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Binding Corporate Rules for intra-group transfers
- Your explicit consent for specific transfers
7. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.
Retention Periods:
- Account Data: Retained while your account is active and for up to 2 years after account closure
- Workshop Content: Retained for the duration of your enrollment plus 1 year for reference purposes
- Payment Records: Retained for 7 years to comply with financial regulations
- Marketing Data: Retained until you withdraw consent or for 3 years of inactivity
- Technical Logs: Retained for 90 days to 1 year depending on the type of log
- Support Communications: Retained for 3 years for quality assurance and dispute resolution
After the retention period expires, we securely delete or anonymize your personal data.
8. Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
8.1 Right of Access
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data along with information about how it is processed.
8.2 Right to Rectification
You have the right to request correction of inaccurate personal data and to complete incomplete data.
8.3 Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Deletion is required to comply with a legal obligation
8.4 Right to Restriction of Processing
You have the right to request that we limit the processing of your personal data when:
- You contest the accuracy of the data
- Processing is unlawful but you oppose erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification of legitimate grounds
8.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
8.6 Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes at any time.
8.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the member state of your habitual residence, place of work, or place of the alleged infringement.
8.9 Automated Decision-Making and Profiling
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you, unless such processing is necessary for contract performance, authorized by law, or based on your explicit consent.
9. How to Exercise Your Rights
To exercise any of your rights under GDPR, please contact us using the following methods:
- Email: help@niknu-v2.com
- Phone: +421908254383
- Mail: Polrex Uskan, M. R. Štefánika 54, 036 01, Martin, Slovakia
- Online Form: Available in your account settings on our platform
We will respond to your request within one month of receipt. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
We may request additional information to verify your identity before processing your request to ensure the security of your personal data.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption: Data encrypted in transit using TLS/SSL protocols and at rest using industry-standard encryption
- Access Controls: Role-based access restrictions, multi-factor authentication for staff
- Network Security: Firewalls, intrusion detection systems, regular security audits
- Data Minimization: Collection and retention of only necessary data
- Employee Training: Regular privacy and security training for all personnel
- Vendor Management: Due diligence and contractual safeguards for third-party processors
- Incident Response: Documented procedures for detecting, investigating, and responding to breaches
- Regular Testing: Penetration testing, vulnerability assessments, security reviews
While we strive to protect your personal data, no method of transmission or storage is completely secure. We cannot guarantee absolute security but continuously work to improve our security measures.
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, providing:
- Description of the nature of the breach
- Categories and approximate number of affected data subjects and records
- Contact information for our data protection officer or point of contact
- Likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate harm
12. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our platform. For detailed information about our use of cookies, including types of cookies used, purposes, and your choices regarding cookies, please refer to our separate Cookie Policy.
You can control cookie preferences through your browser settings or our cookie consent tool available on the website.
13. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16 without parental consent.
If we become aware that we have collected personal data from a child under 16 without proper consent, we will take steps to delete that information promptly.
If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately.
14. Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with GDPR requirements.
You can contact our DPO regarding any questions about this policy or our data processing practices:
Data Protection Officer
Email: help@niknu-v2.com
Address: M. R. Štefánika 54, 036 01, Martin, Slovakia
15. Third-Party Links
Our platform may contain links to third-party websites, applications, or services that are not operated by us. We are not responsible for the privacy practices of these third parties.
We encourage you to review the privacy policies of any third-party sites you visit. This GDPR policy applies only to our services.
16. Changes to This Policy
We may update this GDPR policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons.
We will notify you of any material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email notification to your registered email address
- Displaying a prominent notice on our platform
Continued use of our services after changes become effective constitutes acceptance of the updated policy. If you do not agree with the changes, you may close your account.
17. Legal Compliance and Cooperation
We cooperate with regulatory authorities and comply with all applicable data protection laws and regulations. We respond to lawful requests from authorities and may disclose your data when required by law.
We maintain documentation of our processing activities as required by GDPR Article 30 and conduct Data Protection Impact Assessments (DPIAs) for high-risk processing operations.
18. Your California Privacy Rights (CCPA)
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA). While this policy primarily addresses GDPR compliance, we respect the privacy rights of all users regardless of location.
For information about CCPA rights and how to exercise them, please refer to our separate CCPA Privacy Notice or contact us directly.
19. Contact Information
If you have any questions, concerns, or requests regarding this GDPR policy or our data processing practices, please contact us:
Polrex Uskan
M. R. Štefánika 54
036 01, Martin, Slovakia
Email: help@niknu-v2.com
Phone: +421908254383
WhatsApp: https://wa.me/421908254383
Telegram: https://t.me/+421908254383
We are committed to resolving complaints about our collection or use of your personal data. If you have concerns about how we handle your personal data, please contact us first so we can attempt to resolve the issue.
20. Supervisory Authority
You have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data violates applicable data protection law.
For residents of Slovakia, the supervisory authority is:
Office for Personal Data Protection of the Slovak Republic
Hraničná 12
820 07 Bratislava 27
Slovak Republic
You may also contact the supervisory authority in your country of habitual residence or place of work if different from Slovakia.
This GDPR Compliance policy was last updated on October 26, 2025, and is effective immediately for all users of Polrex Uskan services.