Privacy policy
This page describes personal-data processing in the NODERA public frontend, customer account, payments, and managed services.
Controller and contact
Controller: REDMOTION s. r. o., Karpatské námestie 10, 831 06 Bratislava, Slovak Republic, Company ID 47 195 819, Tax ID 2023793750, registered in the Commercial Register of the Municipal Court Bratislava III, section Sro, file 89869/B. The company is not registered for VAT.
The public website is nodera.sk. For legal questions and data-rights requests, use only legal@nodera.sk and send the message from the order e-mail or the current verified e-mail of the account concerned.
Data we process
The scope depends on whether you only read public pages or actively use an account, form, message, subscription, article rating, or optional measurement.
- Technical data: IP address, user agent, request time, referrer, security and server logs, and a daily pseudonymous visitor value used by first-party blog statistics.
- Account, order, and billing data: contact e-mail, username or display name, the selected Google, Discord, or Steam identifier, verification state, profile and billing details, immutable order snapshots, and authentication session identifiers.
- Contact and support data: name, e-mail, message, form identifiers, submission time, IP address, user agent, referrer, and reCAPTCHA result where enabled.
- Communication data: private messages, recipients, newsletter subscription state, and the content and metadata of interactions initiated by the user.
- Cookies and preferences: language, session, article-rating state, consent choice, and optional Google analytics or marketing identifiers after consent.
Purposes and legal bases
Each purpose must have its own legal basis. A privacy notice is information, not a blanket consent request.
- Delivering pages, sessions, security, abuse prevention, and requested functions: performance of a requested service and the controller's legitimate interest in secure operation, as applicable.
- Accounts, authentication, messages, subscriptions, and user-requested functions: steps requested by the user and performance of the relevant service relationship.
- Contact and support: responding to a request, pre-contractual communication where applicable, and legitimate interest in handling enquiries and protecting the service.
- First-party operational statistics: legitimate interest subject to a documented balancing assessment; Google analytics and marketing: consent through cookie settings.
- Accounting, disputes, legal claims, and compliance: the applicable legal obligation or establishment, exercise, or defence of legal claims.
Recipients, providers, and transfers
Access should be limited to authorized administrators and providers needed for the selected function. Personal data must not be disclosed for another party's own marketing without a valid legal basis.
Hosting, e-mail, payment, authentication, and infrastructure providers act only to the extent needed for their service and under applicable data-protection terms. Transfers outside the EU/EEA use an applicable adequacy decision or contractual safeguards where required.
- Hosting, database, e-mail, and technical infrastructure providers used to operate NODERA.
- Google reCAPTCHA when the visitor submits a protected form.
- Google Analytics and tags delivered through Google Tag Manager only after the corresponding consent; Stripe for payment and billing; Google, Discord, or Steam when the user chooses that sign-in provider.
- Jost is served directly from Nodera infrastructure, so opening a public page does not send a Google Fonts request.
- Authorized Nodera administrators to the extent needed for support, security, and operation.
Retention
Data is kept only as long as needed for the stated purpose, security, service delivery, disputes, or a legal obligation. Account and contract records are kept for the contractual relationship and applicable statutory periods; support records are normally kept for up to 24 months after resolution, unless a claim or law requires longer retention.
nodera_locale and nodera_cookie_consent last 12 months; the PHP session and blog rating marker last for the browser session. Security logs are normally kept for up to 12 months and optional-provider retention follows the current cookie inventory and provider settings.
Your rights
Depending on the legal basis and circumstances, you may request access, rectification, erasure, restriction, portability, object to processing, or withdraw consent without affecting processing that occurred before withdrawal.
- Send requests to legal@nodera.sk from the order e-mail or the current verified account e-mail; reasonable identity verification may be requested where necessary.
- Identity may need to be reasonably verified before account-specific data is disclosed or changed.
- You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic or another competent supervisory authority.
Automated decision-making
NODERA does not use automated decision-making or profiling that produces legal or similarly significant effects. Automated fraud and security signals may be used to protect payments and the service, with human review available where appropriate.
Security
The current runtime uses HttpOnly and SameSite session settings, CSRF-related session state, password hashing, reCAPTCHA-based form protection where enabled, security headers, and role-based administration. No measure can eliminate every risk; security or privacy concerns may be reported to legal@nodera.sk.