Important documents
General terms and conditions
GENERAL TERMS AND CONDITIONS (v. 1, effective as of 15/08/2026)
EFRATA s.r.o. for the provision of consulting services, services in the field of personal data protection (GDPR), performance of the function of Data Protection Officer (DPO), compliance and related services
Article I. Introductory Provisions
1.1 These General Terms and Conditions (hereinafter the "GTC") govern the rights and obligations of EFRATA s.r.o., with its registered office at Nám. kpt. Nálepku 689/21, 082 04 Drienov, Company ID No.: 57 816 638, registered in the Commercial Register of the District Court Prešov, Section: Sro, Insert No. 53393/P (hereinafter the "Provider"), and its clients (hereinafter the "Client") in the provision of services specified in Article II of these GTC.
1.2 These GTC form an integral part of every contract concluded between the Provider and the Client, unless a specific contract provides otherwise. In the event of a conflict between the GTC and individually agreed contractual terms, the individually agreed terms shall prevail.
1.3 The Client may be:
- a natural person – entrepreneur,
- a legal entity,
- a natural person – consumer within the meaning of Act No. 108/2024 Coll. on Consumer Protection and on Amendments to Certain Acts (hereinafter the "Client – Consumer").
Special provisions relating to the Client – Consumer are set out in Article XII of these GTC.
Article II. Subject of Services
2.1 On the basis of a contract with the Client, the Provider mainly provides the following services:
- business and personnel/HR consulting in the field of labour law, to the extent that does not constitute the practice of advocacy (legal profession);
- consulting and compliance services;
- services in the field of personal data protection under the GDPR and Act No. 18/2018 Coll.;
- performance of the function of external Data Protection Officer (DPO);
- personal data protection audits and internal audits;
- preparation of GDPR documentation and internal directives;
- risk analyses and data protection impact assessments (DPIA);
- training of company management, employees and other persons;
- consultations and cooperation in dealing with security incidents;
- consulting in the field of information security;
- preparation of documentation according to the Client’s individual requirements;
- other consulting services as individually agreed.
2.2 The Provider does not provide legal services within the meaning of Act No. 586/2003 Coll. on Advocacy (in particular representation before courts and public authorities, provision of legal advice beyond HR/compliance consulting and drafting of documents on legal acts), unless expressly agreed otherwise and such service is provided in cooperation with a cooperating law firm. For individual legal issues and for the preparation of binding contractual documentation, the Client is recommended to consult a lawyer.
Article III. Conclusion of the Contract
3.1 The contractual relationship between the Provider and the Client is established in particular by:
signing a written contract (e.g. a Service Contract, a Contract on the performance of the function of a responsible person),
confirmation of the price offer by the Client,
confirmation of the Client's order by the Provider (by e-mail or via an electronic system),
commencement of the provision of the service based on the Client's order.
3.2 The Client's order is binding from the moment of its confirmation by the Provider. By sending the order or signing the contract, the Client confirms that he has familiarized himself with these GTC, understood their content and agrees with them.
3.3 Before bindingly ordering the service, the Client - consumer has the opportunity to check and change the data he entered into the order in order to identify and correct any errors.
Article IV. Price and payment terms
4.1 The price of services is determined by:
individual price offer,
hourly rate,
flat monthly fee,
project price,
or. according to the current Price List of the Provider's services.
4.2 Unless otherwise agreed, prices are stated excluding VAT; the Provider is not a VAT payer.
4.3 The Provider is entitled to request an advance payment before the start of the provision of the service, especially for one-off projects (e.g. initial GDPR audit).
4.4 For repeated/flat-rate services (e.g. performance of DPO), the fee is payable monthly in advance, unless otherwise agreed.
4.5 The maturity of invoices is 14 days from the date of their issue, unless otherwise agreed.
4.6 If the Client – entrepreneur is late with payment, the Provider shall be entitled to statutory interest on arrears and to a lump sum compensation for costs associated with the exercise of the claim pursuant to Government Regulation No. 21/2013 Coll. If the Client – consumer is late, the Provider shall be entitled to statutory interest on arrears pursuant to the Civil Code. In both cases, the Provider is entitled to suspend the provision of services until the payment of the due remuneration.
Article V. Client Obligations
5.1 The Client undertakes to:
provide the Provider with true and complete information and documents,
submit the necessary documents on time and provide the cooperation necessary for the proper provision of the service,
immediately notify of any change in data relevant to the provision of the service,
respect the Provider's professional instructions related to the provision of the service,
pay the agreed remuneration properly and on time.
5.2 The Client is responsible for the accuracy and completeness of the documents submitted to the Provider. The Provider is not liable for the consequences of incomplete, incorrect or late information and documents provided by the Client, nor for delays caused by the Client's lack of cooperation.
Article VI. Obligations of the Provider
6.1 The Provider undertakes to:
provide services professionally, with professional care and in accordance with the applicable legal regulations of the Slovak Republic and the European Union,
maintain confidentiality and protect the Client's confidential information,
comply with the GDPR and Act No. 18/2018 Coll. when processing personal data.
6.2 The Services are provided mainly remotely (e-mail, telephone, online communication); personal meetings are held by mutual agreement of the Contracting Parties.
6.3 The Provider is entitled to entrust the provision of part of the service to a professionally qualified third party (subcontractor) bound by confidentiality, while the liability to the Client is not affected by this.
Article VII. Performance of the function of the responsible person (DPO)
7.1 If the Provider, based on a separate contract or authorization, performs the function of the responsible person (DPO) for the Client:
performs it independently, in accordance with Article 38(3) of the GDPR, and does not receive instructions regarding the performance of this function,
the Client is obliged to provide and ensure the necessary cooperation and resources for its performance,
the Client remains the controller of personal data and is responsible for compliance of processing with the GDPR,
the Provider is not liable for violations of the GDPR caused by the Client or its employees, unless the Provider has demonstrably pointed them out.
7.2 The Provider may use professional collaborators bound by confidentiality when performing the function of the DPO.
Article VIII. Intellectual property
8.1 All documentation, methodologies, templates, analyses, training materials and presentations created by the Provider in the provision of services remain the subject of the copyright of the Provider, unless otherwise agreed.
8.2 The Client is authorized to use these materials only for its own internal purposes related to the subject of the contract.
8.3 Without the prior written consent of the Provider, the Client is not authorized to copy, sell, distribute or provide these materials to third parties beyond the scope of point 8.2.
Article IX. Confidentiality and protection of personal data
9.1 Both Contracting Parties are obliged to maintain confidentiality of all confidential facts that they learned during the performance of the contract. This obligation continues even after the termination of cooperation.
9.2 When processing personal data on behalf of the Client, the Provider proceeds in accordance with the GDPR and the concluded Personal Data Processing Agreement (Article 28 GDPR), if relevant for a specific service.
9.3 Information on the processing of personal data of the Client himself (as the data subject) by the Provider is provided in a separate Personal Data Protection Policy published on the Provider's website.
Article X. Liability for damage and limitation of liability
10.1 The Provider is liable for damage caused by a culpable breach of its obligations.
10.2 The Provider is not liable in particular for:
lost profits and indirect damage,
sanctions imposed on the Client due to the Client's failure to provide cooperation,
decisions of public authorities,
damage caused by false, incomplete or late data and documents provided by the Client.
10.3 In relation to the Client - entrepreneur, the Provider's total liability for damage is limited to the amount of compensation paid by the Client for the period of 12 months preceding the occurrence of the damage, except in cases of intentional conduct or gross negligence.
10.4 This limitation shall not apply to the Client - consumer to the extent that it would be in conflict with mandatory consumer protection provisions.
Article XI. Duration and termination of cooperation
11.1 The contractual relationship may be terminated:
by written agreement of the Contracting Parties,
by termination,
by withdrawal pursuant to law or contract,
by expiry of the period for which it was agreed.
11.2 Unless otherwise agreed, the notice period is 1 (one) calendar month and begins on the first day of the calendar month following the delivery of the notice to the other Contracting Party.
11.3 Withdrawal from the contract shall take effect on the date of delivery of the written withdrawal to the other Contracting Party.
Article XII. Complaints
12.1 The Client is obliged to point out defects in the provided service without undue delay after their discovery. The complaint must contain the Client's identification, a description of the defect and the requested method of handling.
12.2 The detailed procedure for handling complaints from the Client - consumer is regulated by the Provider's Complaints Procedure, published on its website. The Provider issues the Complaints Procedure voluntarily, beyond its legal obligations under Act No. 108/2024 Coll., in order to transparently inform Clients about the procedure for handling complaints.
12.3 The Client - consumer has rights under Act No. 108/2024 Coll. on consumer protection and related legal regulations.
Article XIII. Special provisions for the Client - Consumer
13.1 The Client - Consumer is entitled to withdraw from a contract concluded at a distance or outside the Provider's premises without giving a reason within 14 days from the date of conclusion of the contract, in accordance with Act No. 108/2024 Coll.
13.2 If the Client - Consumer has expressly requested the commencement of the provision of the service before the expiry of the withdrawal period, he is obliged to pay the Provider the price for the performance actually provided until the moment of withdrawal from the contract.
13.3 The right to withdraw from the contract does not apply to contracts whose subject matter is the provision of a service, if its provision began with the explicit consent of the Client - Consumer, who declared that he was duly informed that by expressing this consent he loses the right to withdraw from the contract after the service has been fully provided, and if the service has been fully provided.
13.4 If the Provider allows the conclusion of a contract via its website (online order form or similar interface), it shall ensure, in accordance with Section 20a of Act No. 108/2024 Coll. (effective from 19. 6. 2026), a clearly accessible button or similar function in this interface enabling the Client – consumer to easily withdraw from the contract thus concluded.
13.5 The supervisory authority is the Slovak Trade Inspection (SOI), SOI Inspectorate with its registered office in Prešov for the Prešov Region, Obrancov mieru 6, 080 01 Prešov. The Client – consumer has the right to contact the Provider with a request for redress if he is not satisfied with the manner in which the complaint was handled or believes that the Provider has violated his rights. If the Provider responds negatively to this request or does not respond to it within 30 days, the Client - consumer has the right to submit a proposal to initiate alternative dispute resolution (ADR) pursuant to Act No. 391/2015 Coll., for example, via the platform available at https://www.soi.sk/sk/alternativne-riesenie-spotrebitelskych-sporov.html, or the European Commission's RSO online platform.
Article XIV. Force Majeure
14.1 None of the Contracting Parties is liable for failure to fulfill obligations caused by events excluding liability (force majeure) that it could not reasonably foresee or influence.
Article XV. Delivery
15.1 Documents delivered by e-mail, to an electronic mailbox, by post or by courier are considered delivered.
15.2 An e-mail is considered delivered on the next business day after it is sent, unless proven otherwise.
Article XVI. Dispute Resolution
16.1 Legal relationships not expressly regulated by this Agreement are governed by the Commercial Code (in relation to the Client - entrepreneur), or the Civil Code and Act No. 108/2024 Coll. (in relation to the Client - consumer), and other generally binding legal regulations of the Slovak Republic.
16.2 Disputes arising between the Provider and the Client are resolved primarily by agreement; if this is not achieved, the courts of the Slovak Republic are competent, or the procedure according to Article XIII, point 13.5 of these GTC is applicable.
Article XVII. Final Provisions
17.1 These GTC enter into force and effect on 15. 08. 2026 and are published on the Provider's website www.efrata.eu.
17.2 The Provider is entitled to amend these GTC accordingly; The change is effective from the date of its publication, unless otherwise specified. Contractual relationships established before the change to the GTC are subject to the GTC effective at the time of their creation, unless otherwise agreed.
17.3 If any provision of these GTC becomes invalid or ineffective, the validity of the other provisions is not affected.
In Drienov, on 15. 08. 2026
EFRATA s.r.o.
Data protection
PRINCIPLES OF PERSONAL DATA PROTECTION (v. 1, effective from 15/08/2026)
1. IDENTIFICATION OF THE CONTROLLER
Business name: EFRATA s.r.o.
Registered office: Nám. Kpt. Nálepku 689/21, 082 04 Drienov
Company ID No.: 57 816 638
Contact e-mail: efrata@efrata.eu
Telephone: +421 905 262 844
2. PURPOSES AND LEGAL BASES OF PROCESSING
Personal data are processed exclusively for the following purposes:
2.1 Provision of consulting services
Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Personal data necessary for the provision of the consulting service ordered are processed.
2.2 Bookkeeping and invoicing
Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR). Data on invoices are processed in accordance with Act No. 431/2002 Coll. on Accounting.
2.3 Communication with the client
Legal basis: legitimate interest of the controller (Art. 6(1)(f) GDPR) – management of client relationships and responding to enquiries.
2.4 Sending commercial offers (only with consent)
Legal basis: consent of the data subject (Art. 6(1)(a) GDPR). This consent may be withdrawn at any time.
3. SCOPE OF PROCESSED PERSONAL DATA
We only process personal data that is necessary for the given purpose (minimization principle). This includes in particular:
identification data: name, surname, title;
contact data: address, e-mail, telephone number;
billing data: address, company ID, VAT number (for entrepreneurs);
data related to the advisory service: information that you provide us with during the consultation.
We process special categories of personal data (sensitive data) only if it is necessary to provide a specific advisory service and always based on your explicit consent.
4. RECIPIENTS OF PERSONAL DATA
We do not sell or rent your personal data to third parties. We may provide it to:
an accountant / tax advisor - for accounting purposes;
to IT service providers - based on a personal data processing agreement;
to public authorities - if required to do so by law.
5. STORAGE PERIOD
We store personal data only for the period necessary for the given purpose:
contractual documents and invoices: 10 years (Accounting Act);
correspondence and records of consultations: 3 years from the end of cooperation;
marketing consent: until its withdrawal, at most 3 years.
6. YOUR RIGHTS
As a data subject, you have the following rights:
right to access your personal data (Art. 15 GDPR);
right to correct incorrect data (Art. 16 GDPR);
right to erasure - right to be forgotten (Art. 17 GDPR);
right to restriction of processing (Art. 18 GDPR);
right to data portability (Art. 20 GDPR);
right to object to processing (Art. 21 GDPR);
right to withdraw consent at any time without giving a reason;
the right to file a complaint with the Personal Data Protection Office of the Slovak Republic (www.dataprotection.gov.sk).
Send requests for exercising your rights to: efrata@efrata.eu. We will respond to your request within 30 days.
7. DATA SECURITY
We have adopted appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure or destruction. Personal data in paper form is stored in locked premises.
8. COOKIES
On the website www.efrata.eu, we use only essential cookies, without which our website cannot function.
9. CHANGES TO THE POLICY
We may update this policy. We will inform you of any significant changes by e-mail or by posting it on the website. The current version is always available upon request.
10. CONTACT
For questions related to personal data protection, please contact us at: efrata@efrata.eu or +421 905 262 844.
Billing information
Business name
EFRATA, s. r. o.
Registered office
Námestie kpt. Nálepku 689/21, 082 04 Drienov
Company ID
57 816 638
Tax ID
2123140492
Registration
Commercial Register of the District Court Prešov, Section: Sro, Insert No. 53993/P
Statutory body
JUDr. Michaela Sopková, Managing Director
Bank details
Slovenská sporiteľňa, a. s.
IBAN
SK93 0900 0000 0052 5233 2502
SWIFT/BIC
GIBASKBX
E-mail (invoicing)
faktury@efrata.eu
Telephone
+421 905 262 844
Notes for clients
• When paying an invoice, please include the variable symbol that matches the invoice number.
• Invoices are issued electronically and sent to the email address specified in the contract/order.
• In the event of a change in billing information, we will inform clients by updating this document.