Personal data processing principles — the Dalinora application and clients. Effective as of 28 August 2026.
Welcome to our unique Dalinora application, thanks to which your investing will from now on be clear, understandable, and transparent. And that also thanks to the built-in AI, ready to advise you and answer any questions about investing and financial products.
And all in one place — in the Dalinora mobile application, created by experts in technology and investment. No more lengthy watching of videos or reading of disjointed texts from which you only learn that you are none the wiser about investing. Our Dalinora application is here so that you can focus only on what matters most — how to protect and multiply your money to the maximum.
Before registering in our Dalinora application, please read these Personal Data Processing Principles (the “Principles”) carefully. In them you will find everything you need to know about how, through the Dalinora application, we handle your personal data under Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”), Act No. 18/2018 Coll. on personal data protection, and Act No. 186/2009 Coll. on financial intermediation and financial advisory services (the “Act”), in connection with the processing of your personal data through the Dalinora mobile application and our website www.dalinora.com.
Note: Terms with an initial capital letter that are not defined directly in these Principles have the meaning set out in the Company’s General Terms and Conditions (GTC).
Here you will find the necessary information if you are (i) a user of our unique Dalinora mobile application (the “Application”) and later (ii) a potential client and (iii) a client to whom financial intermediation is provided (after conclusion of the financial intermediation contract) (the “Client”), as well as (iv) a visitor to our website www.dalinora.com (the “Website”), where these Principles apply to them by their nature.
You become a Client, and thus a data subject (i.e. a person whose personal data we process), the moment you download the Application to your phone. As soon as you register, we process your personal data for the entire duration of your user account in the Application.
To create a user account in our Application and subsequently use its functionalities on the basis of the Financial Intermediation Contract, all conditions set out in our General Terms and Conditions for concluding a financial intermediation contract at a distance must be met.
The controller, i.e. the entity that handles your personal data as Clients (and Website visitors) in its own name for the purposes set out below, is the company Dalinora, s. r. o., registered office: Pribinova 10, 811 09 Bratislava – Staré Mesto district, Slovak Republic, ID No.: 57 430 471, registered in the Commercial Register of the Bratislava III Municipal Court, section: Sro, insert No.: 195826/B (the “we” or the “Controller”).
Do you have any questions about personal data? Feel free to write us an e-mail at gdpr@dalinora.com.
The Controller fully respects your privacy and approaches the protection of your personal data with the utmost professional care. For the purpose of carrying out financial intermediation, in particular to ensure the digital conclusion of the Financial Intermediation Contract and, on your instruction, also the Intermediated Contract, we need to obtain personal data from you that will be used to provide these services, to communicate, and to fulfil legal obligations. The Company ensures the protection of all data in accordance with Regulation (EU) 2016/679 (GDPR) (or Act No. 18/2018 Coll. on personal data protection) and the Act on financial intermediation.
The purpose of processing personal data is the reason for which we, as the Controller, process your personal data. For each purpose we need a legal basis, which answers the question of why we may or must process your personal data for each individual purpose. We always process your personal data only to the extent necessary and only for the following processing purposes:
After downloading the Application, you have the option to register in it. Before registration, it is necessary to complete a questionnaire that helps us understand what type of investor you are and which investment product is most suitable for you. After entering your data, we will ask you to duly study the submitted documents, including the General Terms and Conditions and these Personal Data Processing Principles, and to create your user account.
At this moment the Registration Contract is concluded between us, which allows you to create and manage your user account in the Application and to use the related Application functionalities in accordance with its current setup and the conditions set out in the General Terms and Conditions.
We may also use your e-mail (and, where applicable, your phone number) to send important information related to our contractual relationship or where sending it is our legal obligation (e.g. information about successful registration, changes to our general terms and conditions, changes to or addition of new Application functionalities, possible unavailability of the Application or some of its functionalities, etc.). Your phone number will be used to verify you when creating your user account and later to conclude contracts and individual acts in the Application through your authorisation by entering an SMS code.
For the purpose of creating and managing your user account in the Application, making the Client Zone accessible in the Application, and verifying your identity (KYC – Know Your Client, processes for establishing and verifying the client’s identity – including screening of sanctions and PEP lists), we process in particular the following categories of personal data: name, surname, permanent residence, birth number, date of birth, nationality, type and number of identity document; contact details (e-mail address, phone number).
The provision and processing of personal data for this purpose is a contractual requirement and a requirement necessary for concluding a contract with the data subject. Without providing the required personal data and our subsequent processing of it, the Registration Contract in the Application cannot be concluded or performed (i.e. we cannot create a user account for you).
For the purposes of carrying out financial intermediation for you, assessing the suitability or appropriateness of a financial service on the basis of your data from the investment questionnaire, the digital conclusion of the Financial Intermediation Contract and subsequently the Intermediated Contract, in addition to the data listed above we also process: bank connection data (in particular account holder name, IBAN, SWIFT/BIC, account currency); data on your financial situation, investment profile, suitability and appropriateness questionnaires, and the parameters of planned saving or investing (in particular target amount, saving period, allocation to funds, risk profile, fee settings), etc.
On the basis of the Financial Intermediation Contract, we are obliged to provide your personal data for processing to the Financial Institution for the purposes of concluding and performing the Intermediated Contract between you and the Financial Institution (in particular for the purposes of opening an asset account and executing orders) and to the National Bank of Slovakia for the purposes of supervision. The transfer of data to Financial Institutions usually takes place through automated API integration or in another agreed electronic format ensuring data integrity. Providing this data is both a contractual and a legal requirement, and without providing it the Financial Intermediation Contract cannot be concluded and performed in accordance with the law.
Legal basis: taking measures prior to concluding a contract and fulfilling obligations arising from the contract (the Registration Contract and the Financial Intermediation Contract) under Art. 6(1)(b) GDPR; fulfilling legal obligations under § 31 of the Act (identification and verification of identification, AML) under Art. 6(1)(c) GDPR.
Processing period: for the duration of the Financial Intermediation Contract (which is conditional on the duration of the Registration Contract and vice versa); data obtained on the basis of the law during identification and verification of identification must be retained for the period set by law (for 5 years from the end of our contractual relationship). If, as a Client, you do not provide us with your personal data to the extent required for registration or by law for concluding the Financial Intermediation Contract, these contracts will not be concluded, as in such a case we may not provide you with financial intermediation.
Under the law, before concluding the Financial Intermediation Contract we are obliged to thoroughly verify your identity. As this is remote verification, we are obliged to do so by biometric verification of your identity, which is considered equivalent to identity verification in your personal presence.
For these purposes we will process your biometric data to the extent of a facial image and technical parameters of the face for the purpose of remote identity verification (Face-match) within the Application (by comparison with the image of your face on your identity document); the processing of this biometric data is carried out on the basis of your express consent granted in the process before concluding the Financial Intermediation Contract. The data needed for biometric verification as well as the result of the verification are retained by us.
We obtain personal data from the identity document, including the facial image, through automated Application processes (e.g. scanning the document or uploading a scan of the document), to the extent necessary to achieve the purpose of processing and in accordance with technical standards for digital identification, and we compare these with a photograph of your face that you create in the Application.
Our Application also offers the option of logging in through the biometric verification functionality available on your mobile phone. In such a case the Application does not obtain or store the biometric data stored on your phone; it only receives the result of biometric verification via your face or fingerprint for the purpose of your login to the Application, which takes place at the level of your mobile phone as its native function, i.e. Face ID (face verification) or fingerprint verification; if you do not choose to log in to the Application using biometrics, you can log in by verification via SMS and password (or via a shorter passcode, if only a short time has elapsed since your last login and you have not been fully logged out of the Application).
Legal basis: your express consent to the processing of your biometric data for your biometric verification for the purposes of (i) verifying your identity before concluding the Financial Intermediation Contract and providing you with financial intermediation under the law, and (ii) your login to the Application (if you choose this method of identity verification before logging in).
Processing period: biometric verification before concluding the Financial Intermediation Contract is retained for the period set by law, in particular the act on protection against money laundering (for 5 years from the end of our contractual relationship).
Within the Application you enter into direct interaction with the AI Chatbot, which serves solely as a communication interface – it communicates with you and conveys the results generated by the Application’s Underlying Algorithms. The AI Chatbot does not itself carry out expert assessment, does not execute financial operations, and does not make independent investment decisions. The processing of your personal data for the purposes of communication with the AI chatbot is carried out for the purposes of performing the contract under point A) above.
For the purpose of improving our communication services via the AI chatbot and other Application functionalities, we may, for your greater comfort and more effective use of the Application, also process data from your interaction with the AI Chatbot beyond the performance of the Registration Contract or the Financial Intermediation Contract (e.g. for the purposes of improving the conversational interface and user comfort) and for the purposes of fulfilling legal archiving obligations under Art. 6(1)(c) GDPR.
Legal basis: the Controller’s legitimate interest in improving communication services via the AI chatbot and Application functionalities under Art. 6(1)(f) GDPR. Under Art. 21 GDPR you have the right to object, on grounds relating to your particular situation, to the processing of your personal data based on the Controller’s legitimate interests. You will find more information in sections 8 and 9 of this notice (your rights and their exercise).
Processing period: (i) for the purposes of improving services: for the duration of the Registration Contract and subsequently for a maximum of 3 years from the cancellation of your registration in the Application; (ii) for the purposes of fulfilling legal archiving obligations (in particular under the Act on financial intermediation and the Act on securities): for a period of 5 years from the day on which the communication between you as a Client and the AI chatbot took place. The provision and processing of personal data for the purpose of improving services is not a legal or contractual requirement or a requirement necessary for concluding a contract, but is based on the Controller’s legitimate interest. Data archiving is our legal obligation.
Outputs and investment recommendations (including the Suitability Statement) are generated exclusively by the Application’s Underlying Algorithms on the basis of mathematical and scoring models that evaluate the information you entered into the investment questionnaire in the Application. These are firmly defined software procedures and mathematical formulas (code) operating on the principle of predefined logical rules and calculations. The Underlying Algorithms do not use artificial intelligence or machine learning technology. Their sole task is to mathematically evaluate the Client’s answers in the investment questionnaire and, on the basis of fixed rules approved by the professional guarantor, assign the Client a corresponding investment solution of a partner Financial Institution. This ensures that investment recommendations are always predictable, precisely traceable, and independent of the AI Chatbot’s conversational abilities.
This processing of data via the Underlying Algorithms constitutes automated individual decision-making (including profiling) within the meaning of Art. 22 GDPR. Below we inform you of the procedure used, as well as of the significance and envisaged consequences of such processing:
Procedure used (logic): The Underlying Algorithms mathematically evaluate your answers in the investment questionnaire (e.g. financial situation, knowledge and experience, ability to bear loss, investment objectives, risk profile) and, on the basis of fixed rules approved by the Controller’s professional guarantor, assign a corresponding investment solution of a partner Financial Institution.
Neutrality of the algorithms: the amount of commissions paid by Financial Institutions in no way enters the calculation formulas and has no influence on the selection or order of recommended products; the compliance of the Underlying Algorithms with legislation (in particular MiFID II and the SA) is regularly tested and audited by the Controller’s professional guarantor.
Significance and envisaged consequences: the output of the processing of the information you provided by the Underlying Algorithms determines which investment, insurance, or pension solution will be recommended to you and may thus have a direct impact on the content of the Intermediated Contract you conclude with the Financial Institution.
In this regard, you have the right not to be subject to such automated decision-making. Within this, you have the right to a) at any time ask the Controller for a non-automated (human) review of the suitability and appropriateness of specific investment products for you and of the Underlying Algorithms’ recommendations, b) express your opinion, and c) contest the result of the Underlying Algorithms’ assessment. On the basis of your request delivered to the e-mail address made available to you for this purpose in the Application, we will without undue delay ensure an individual assessment of your situation by a human – the Company’s professional guarantor or a professional employee authorised by them. We will send you the resulting opinion in writing in PDF format to the Client Zone in the Application and to your verified e-mail address.
Legal basis: processing is necessary for concluding and performing the Financial Intermediation Contract between you and the Company under Art. 22(2)(a) GDPR in conjunction with Art. 6(1)(b) GDPR. Processing period: for the duration of the Financial Intermediation Contract. The provision and processing of this data is a contractual requirement, and without providing it the Financial Intermediation Contract cannot be concluded and performed in accordance with the law.
If you are interested in the world of investing, we have a regular newsletter for you, full of financial news and all the information you should know to stay informed in the investment world. All you need to do is grant us your consent to receiving the newsletter when you register in the Application or at any time later.
Legal basis: your consent under Art. 6(1)(a) GDPR. You may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of the processing of your personal data before its withdrawal.
Processing period: until withdrawal of consent, at the latest until cancellation of your user account in the Application, whichever occurs first. The processing of personal data for this purpose is not a contractual or legal requirement, but is based on your voluntarily granted consent.
As an entrepreneur and regulated financial agent, our company is subject to several legal obligations that we are required to fulfil (e.g. in the area of prevention of money laundering – AML, regulation of financial intermediation, bookkeeping, personal data protection, consumer protection, etc.). For the purposes of their proper fulfilment, it is necessary to process certain personal data of Application users as our Clients, to the extent and for the period set by the relevant legislation or determined on its basis by us or a public authority, even after the end of our contractual relationship.
Legal basis: fulfilment of obligations arising for us from legislation under Art. 6(1)(c) GDPR. Processing period: for the period set by legislation or on its basis. The processing of personal data for this purpose is a requirement arising for us from the relevant legislation, and without processing it we would not be able to fulfil our legal obligations. If, as a Client, you do not provide us with personal data to the extent required by the Act on financial intermediation, we may not provide you with financial intermediation.
For the purpose of exercising or defending our rights and claims – for example asserting our right to proper compliance with our general terms and conditions, payment of our receivables from our contractual partners, claiming compensation for damage incurred by us or a third party (e.g. our business partners), proving misuse of access to the Application or its intentional damage, initiating or defending rights and claims within specific out-of-court or possible court proceedings, preparing evidence to demonstrate the compliance of our activity with legislation, and demonstrating fulfilment of our obligations, primarily towards public authorities – we may also process your personal data to the extent necessary. The scope of the personal data processed will depend on the type of proceedings or the right or claim being asserted or defended.
Legal basis: the legitimate interest of the Controller or a third party in exercising and defending rights and claims under Art. 6(1)(f) GDPR. Under Art. 21 GDPR you have the right to object, on grounds relating to your particular situation, to the processing of your personal data based on the Controller’s legitimate interests. You will find more information in sections 8 and 9 of this notice (your rights and their exercise).
Processing period: for the period set under legislation during which we are entitled to exercise or defend our rights and claims (limitation or preclusion period) or may bear legal consequences for failure to fulfil obligations imposed by law, e.g. in the form of a sanction imposed by public authorities. The provision and processing of personal data for this purpose is not a legal or contractual requirement or a requirement necessary for concluding a contract, but is based on the Controller’s legitimate interest.
The Application and the Client Zone in the Application are protected by personalised access credentials. Access to the Application on first login is secured by multi-factor authentication (MFA), comprising a combination of a) phone number, b) password, and c) a one-time verification code delivered via SMS or e-mail. After successful login, repeated access to the Application is verified via (i) biometric verification or (ii) verification via SMS and entry of a password, or a shorter personal access code (passcode) on your mobile device. These security elements serve for your unambiguous identification and authorisation of your acts in the Application.
To ensure the protection of our information systems, as well as the information stored via the Application and on the Website, including personal data, and to ensure the availability of our Application, its functionalities, and the Website, we adopt and regularly update all relevant security measures. However, for this purpose too it is necessary to process, to the extent necessary, certain personal data generated by your device and our system when using Application functionalities and visiting our Website. Thanks to this data we can protect our systems against misuse, e.g. launching bots, sending spam, DOS or DDOS attacks, etc., which could cause malfunction of the Application or Website or unavailability of some of their functionalities, or unauthorised access to personal or other data contained in our information systems. We process this data to the extent necessary and always subject to the relevant security measures, and it includes in particular login logs to the Application, the IP address, and information about the device from which you log in, etc.
Legal basis: the Controller’s legitimate interest in ensuring the cybersecurity protection of our information systems, including the Application itself, their proper functioning, and the protection of personal and other sensitive data contained in them under Art. 6(1)(f) GDPR. Under Art. 21 GDPR you have the right to object, on grounds relating to your particular situation, to the processing of your personal data based on the Controller’s legitimate interests. You will find more information in sections 8 and 9 of this notice (your rights and their exercise).
Processing period: for the duration of our legitimate interest, which we regularly and carefully monitor, generally 5 years from obtaining the data, in specific cases (primarily on the basis of a request from the National Bank of Slovakia) 7 years from obtaining it. The provision and processing of personal data for this purpose is not a legal or contractual requirement or a requirement necessary for concluding a contract, but is based on the Controller’s legitimate interest.
In our Application we may use online identifiers, in particular cookies, to ensure its proper functioning that you expect from our Application. These cookies are technical and their use does not require your consent. The information stored in technical cookie files will not be used to personally identify you, nor for purposes other than those set out in this text and in the cookie banner displayed on our website or in the Application. We also use analytical and marketing cookies only on the basis of your consent granted via the cookie banner or in another appropriate manner; you may withdraw this consent at any time in the cookie settings in the Application and on the Website, depending on where you no longer want the cookie. You will find more information in our cookie banner in the Application and on the Website.
Legal basis: exemption from consent under § 109(8) of Act No. 452/2021 Coll. on electronic communications; in the case of cookies other than technical ones, consent granted under § 109(8) of Act No. 452/2021 Coll. on electronic communications. Under Art. 21 GDPR you have the right to object, on grounds relating to your particular situation, to the processing of your personal data based on the Controller’s legitimate interests. You will find more information in sections 8 and 9 of this notice (your rights and their exercise).
Processing period: at the latest until you log out of your user account in the Application and end your browsing of the Website; in the case of non-technical cookies, a maximum of 12 months. The provision and processing of personal data for this purpose is not a legal or contractual requirement or a requirement necessary for concluding a contract, but is based on the Controller’s legitimate interest.
As the administrator of the Application, we care greatly that it serves its purpose and that every Client quickly finds their way around it and can start using its functionalities to the full. We therefore need to know how the Application (as well as the Website) is used by our Clients. Thanks to these statistical data we can analyse where the Application has gaps in its functioning or design and come up with better solutions for your satisfaction and its more effective use. Statistical or analytical data are in no case used to identify a Client or a Website visitor.
Legal basis: the Controller’s legitimate interest in the continuous improvement of our Application and its functionalities and thereby securing our right to conduct business under Art. 6(1)(f) GDPR. Under Art. 21 GDPR you have the right to object, on grounds relating to your particular situation, to the processing of your personal data based on the Controller’s legitimate interests. You will find more information in sections 8 and 9 of this notice (your rights and their exercise). Processing period: a maximum of 4 years from the calendar year in which the statistical data were obtained.
We obtain your personal data primarily directly from you as the data subject (during registration, completing the investment questionnaire, communicating with the AI Chatbot, concluding contracts through the Application, and using its other functionalities, or during your visit to our Website).
We may also draw some data from publicly available sources (e.g. sanctions and PEP lists) and from Financial Institutions in connection with performance of the Intermediated Contract. Some data is generated automatically during your interaction with the Application and the Website (e.g. cookies, technical logs). Some data is created by our information systems during your interaction with our Application and Website (e.g. cookies) and some is sent to our systems directly from your device.
We share your personal data processed for the purposes set out above, to the extent necessary, with our processors, i.e. contractual partners who process it on our behalf and solely on our instructions, e.g. various providers of IT solutions, including cloud storage (in the Amazon Web Services (AWS) cloud infrastructure, in encrypted form within the territory of the European Union), bulk e-mail services and analytical services, the provider of the SMS authorisation service (one-time authorisation codes sent to your phone number when registering in the Application and when signing the Contract), as well as accountants, etc.
We also make your personal data available, to the extent necessary, to the following categories of recipients: Financial Institutions with which we have concluded a financial intermediation agreement, for the purposes of performing the Intermediated Contract concluded between the Financial Institution and you as the Client (the transfer of data takes place via automated API integration or in other agreed electronic formats ensuring the confidentiality, integrity, and availability of the data provided); the National Bank of Slovakia for the purposes of supervising our financial intermediation activity; the provider of the biometric identity verification service within KYC (Face-match and identity document verification); tax advisor, auditor, attorneys; etc.
Personal data may further be provided to state authorities and other institutions only where this arises for us from legislation (e.g. to the National Bank of Slovakia as the supervisory authority) or where it is necessary for the defence or exercise of rights and claims. With other entities, some of your personal data is shared due to necessity for the services they provide to us. When selecting entities that provide services to us, we always make sure that they provide adequate guarantees of the security and lawfulness of personal data processing.
We always process personal data for the period necessary to fulfil the stated purpose of processing. This period differs depending on the purpose for which the personal data is processed. We regularly reassess the duration of each processing purpose and, if we find that the processing of personal data is no longer necessary and its processing is not required by legislation either, we erase it even before the originally set processing period expires. You will find the specific processing periods in section 3 under the individual legal bases.
For the purpose of maximum protection of your personal data, we as the Controller have adopted adequate personnel, organisational, and technical measures (in particular encryption of data at rest and in transit, multi-factor authentication for access to the Application, an access management system in the AWS cloud infrastructure, etc.). All data is stored on secure servers with continuous monitoring of its confidentiality, integrity, and availability.
Our goal is to prevent, or to the greatest possible extent reduce, the risk of leakage, misuse, disclosure, or other use of your personal data. We process your personal data within the European Union / European Economic Area. However, in providing our services we also use the services of specialised partners, for example when using specific IT solutions whose provider may be located outside the EU/EEA (in particular in the USA). In such a case, transfer of personal data (in particular by mirroring or backing up servers) to these third countries may take place on their side. In such a case we always carefully verify that each such data transfer is secured in accordance with the GDPR, either on the basis of (i) a European Commission adequacy decision (e.g. in the case of the USA, on the basis of the relevant provider’s certification under the EU-US Data Privacy Framework), or (ii) via standard contractual clauses or other appropriate security measures.
We will provide you on request with the current list of processors and information about the specific mechanism used for transfer to third countries, including a copy of the relevant safeguards, at the contact details set out in this notice. In order to maintain the principle of data minimisation, we always require from you as the data subject only the personal data that is necessary to fulfil the purpose of its processing or whose scope arises from the fulfilment of our legal obligations.
As a data subject, i.e. a person whose personal data is processed, you have the following rights under the GDPR:
A) Right to withdraw consent at any time. You have the right to withdraw your consent to the processing of personal data at any time, without affecting the lawfulness of processing based on consent given before its withdrawal.
B) Right of access to the processed personal data (Art. 15 GDPR). This right includes the right to obtain from us as the Controller confirmation as to whether your personal data as a data subject is being processed, as well as the right to obtain access to this data and to further information under Art. 15 GDPR.
C) Right to rectification (Art. 16 GDPR). As a data subject, you have the right to have us, as the Controller, without undue delay rectify or complete inaccurate or outdated personal data concerning you.
D) Right to erasure (Art. 17 GDPR). As a data subject, you also have the right to ask us, as the Controller, to erase personal data concerning you without undue delay if one of the grounds foreseen by the GDPR is met, in particular if: a) the personal data is no longer necessary for the purposes for which it was collected or otherwise processed; c) the data subject objects to the processing of personal data based on the controller’s legitimate interest and there are no overriding legitimate grounds for the processing; d) the personal data was processed unlawfully; e) the ground for erasure is fulfilment of an obligation under law, a special regulation, or an international treaty by which the Slovak Republic is bound, etc., unless one of the exceptions set out in the GDPR applies. The Controller will erase the personal data on the basis of your request without undue delay after assessing that the request is justified. The Controller is not obliged to erase such personal data in the cases set out in Art. 17(3) GDPR.
E) Right to restriction of processing (Art. 18 GDPR). As a data subject, you have the right to have the Controller restrict the processing of your personal data in one or more of the cases under the GDPR. If the processing of your personal data has been restricted, we will inform you as the data subject before the restriction of processing is lifted.
F) Right to portability (Art. 20 GDPR). As a data subject, you have the right to obtain the personal data concerning you that you have provided to us, in a structured, commonly used, and machine-readable format, including the right to transmit this data to another controller where technically feasible, provided that: a) the processing is based on your consent or a contract concluded with you, and at the same time b) the processing is carried out by automated means. This right must not adversely affect the rights and freedoms of others.
G) Right to object to processing based on legitimate interest (Art. 21 GDPR). As a data subject, you have the right to object at any time to the processing of your personal data based on legitimate interest, on grounds relating to your particular situation, and the Controller may no longer process your personal data unless it demonstrates compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or grounds for the establishment, exercise, or defence of legal claims.
H) Right to lodge a complaint / a petition to initiate proceedings (§ 100 of Act No. 18/2018 Coll. on personal data protection). If you believe that your rights in connection with the processing of personal data concerning you have been infringed, you have the right to lodge a complaint with: the Office for Personal Data Protection of the Slovak Republic, Galvaniho Business Centrum II, Galvaniho 7/B, Bratislava, website: https://dataprotection.gov.sk/uoou/. You may also lodge a complaint with the personal data protection authority in the EU Member State in which you have your habitual residence or place of work, or where the place of the alleged infringement of your rights or of the GDPR is located.
If you have any question about the processing of your personal data or wish to exercise any of your rights under the GDPR, contact us at any time: a) by e-mail at gdpr@dalinora.com; b) by post at the address of our registered office set out above.
We may update this notice as needed. The current version will always be published on our Website and in the Application. Effective as of: 28 August 2026.