Privacy Policy
Effective from 6 July 2026
Protecting your personal data matters to us. This policy explains what personal data we process, for what purposes, on what legal basis, who we share it with, and what rights you have. We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Slovak Act No. 18/2018 Coll. on Personal Data Protection. This English version is provided for convenience; the Slovak version prevails.
1. Data Controller
The controller of your personal data is Emma Crystal, s.r.o., registered office Rudno nad Hronom 303, 966 51 Rudno nad Hronom, Slovakia, Company ID (IČO): 36 837 687, Tax ID (DIČ): 2022454522, VAT ID: SK2022454522, registered in the Commercial Register of the District Court Nitra, Section: Sro, File No. 20718/N ("we").
- Branch Nová Baňa: Cintorínska 61, 968 01 Nová Baňa, tel. +421 908 084 185
- Branch Žiar nad Hronom: Sládkovičova 18/50, 965 01 Žiar nad Hronom, tel. +421 915 636 116
- Privacy contact: info@emmacrystal.sk
No Data Protection Officer has been appointed; please direct all privacy requests to the e-mail address above.
2. What Data We Process and Why
a) Online appointment booking and payment — first and last name, e-mail, phone number, selected service, branch, date and time, note, and optional company billing details. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Without this data the booking cannot be made.
b) Health data — we collect no health data (a special category of personal data under Art. 9 GDPR) through the website. Medical reports and results of previous examinations are brought to the examination in person, and the health questionnaire is filled in directly at the practice. Such data is processed exclusively in the course of providing eye care by a health professional bound by an obligation of secrecy (Art. 9(2)(h) GDPR), outside the website.
c) Booking note — please do not include information about your health in the optional "note" field; it is intended for organisational information (e.g. first visit, scheduling preferences).
d) Style questionnaire (premium consultation) — your eyewear and style preferences. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
e) E-book and newsletter — e-mail and name when downloading our e-book. Legal basis: consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
f) Invoicing and accounting — billing data processed under a legal obligation (Art. 6(1)(c) GDPR; Slovak Accounting Act No. 431/2002 Coll., VAT Act No. 222/2004 Coll.).
g) Replies to public reviews — if you post a public review (e.g. on Google), we process its content when preparing a reply, based on our legitimate interest (Art. 6(1)(f) GDPR) in protecting our reputation.
h) Communication — if you contact us by e-mail or phone, we process the data needed to handle your request.
i) Client photos for promotion — we take and publish photos of clients (e.g. with their new glasses) on our website or social media exclusively based on your prior demonstrable consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time by e-mailing info@emmacrystal.sk and we will promptly remove the photo.
j) Booking by a referring doctor — if your doctor books an examination for you via our partner portal, we obtain from them your first and last name, e-mail, phone number and any clinical note (health data). Legal basis: steps taken prior to entering into a contract (Art. 6(1)(b) GDPR) and the provision of eye care by a health professional bound by an obligation of secrecy (Art. 9(2)(h) GDPR). We inform you about the booking and about this policy in the confirmation e-mail.
3. Children's Personal Data
Our services include children's vision screening (from 6 months of age) and behavioural optometry for children. A child's appointment is booked by their legal guardian, who provides the child's identification and contact data (name, age) and gives the consents under this policy on the child's behalf. The child's vision and health data is not collected via the website — we obtain it at the practice during the examination.
Children's health data is processed under the same regime as adults' (Art. 9(2)(a) and (h) GDPR), always with the guardian's consent. Photos of children are published only with the guardian's explicit consent.
Our website, e-book and newsletter are not directed at children. If we learn that we have collected data of a child under 16 in connection with information society services without the guardian's consent, we will delete it promptly.
4. Use of Artificial Intelligence
When drafting replies to public reviews we use the Claude AI tool by Anthropic, PBC (USA). Only the text of the public review is submitted to the tool; every suggested reply is reviewed and approved by a human before publication.
We do not enter booking data, health questionnaires or any health data into AI tools. No automated individual decision-making or profiling within the meaning of Art. 22 GDPR takes place.
Anthropic does not use data submitted via its API to train its models. Transfers to the USA are safeguarded in accordance with Chapter V GDPR (EU–U.S. Data Privacy Framework or standard contractual clauses).
5. Recipients (Processors)
The following service providers process data on our behalf under data processing agreements:
- Supabase, Inc. — database (bookings, style questionnaire); data is stored in the European Union (AWS, Ireland region)
- Stripe Payments Europe, Ltd. — online payment processing and invoicing; card data is handled exclusively by Stripe
- Resend, Inc. — transactional e-mails
- Google Ireland Ltd. — appointment calendar (Google Calendar)
- Vercel, Inc. — website hosting
- Anthropic, PBC — AI assistance with replies to public reviews (see Section 4)
- an external accounting firm — processing of accounting documents
We never sell your data or share it with third parties for marketing purposes.
6. Transfers to Third Countries
The database and file storage (Supabase) are located in the European Union. Some of our processors (Stripe, Resend, Vercel, Anthropic) are based in or may process data in the USA. Transfers are safeguarded by the European Commission adequacy decision (EU–U.S. Data Privacy Framework) or standard contractual clauses under Art. 46 GDPR.
7. Retention Periods
- Booking data — 5 years from your last visit (legitimate interest — care for returning clients and establishing and defending legal claims)
- Health questionnaire filled in at the practice — 10 years (professional records of the care provided); not collected via the website
- Accounting documents (invoices) — 10 years (legal obligation)
- Newsletter e-mail — until consent is withdrawn
- Client photos for promotion — until consent is withdrawn
After the retention period expires, data is securely deleted.
8. Your Rights
Under the GDPR you have the right:
- to access your personal data (Art. 15)
- to rectification of inaccurate data (Art. 16)
- to erasure ("right to be forgotten", Art. 17)
- to restriction of processing (Art. 18)
- to data portability (Art. 20)
- to object to processing based on legitimate interest (Art. 21)
- to withdraw consent at any time, without affecting the lawfulness of prior processing
To exercise your rights, e-mail info@emmacrystal.sk. We will respond within one month.
You also have the right to lodge a complaint with the supervisory authority: Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, www.dataprotection.gov.sk.
9. Cookies
Technically necessary cookies — files required for the site's basic functions (e.g. admin sign-in, Stripe payment flow, storing your cookie choice) — do not require your consent under Section 109(8) of Slovak Act No. 452/2021 Coll. on Electronic Communications and are always active.
Analytics cookies (anonymous traffic statistics) and marketing cookies (personalised advertising) are used exclusively with your prior consent, given in the cookie banner on your first visit. Without consent these tools do not run at all.
You can change your decision or withdraw consent at any time using the "Cookie settings" button below on this page.
10. Data Security
We apply appropriate technical and organisational measures: encrypted communication (TLS/HTTPS), row-level security on the database, staff access limited to data needed for their work, and regular system updates.
11. Final Provisions
We may update this policy from time to time; the current version is always published on this page. The provision of our services is governed by our Terms and Conditions.