Last updated: February 14, 2026
This Privacy Policy explains how Syki Group s.r.o. (hereinafter the "controller" or "we") collects, uses and protects your personal data when you visit the grovtic.com website and when you use our services.
1. Controller
The controller of personal data is:
- Company name: Syki Group s.r.o.
- Registered office: Veľkomoravská 2162/16B, 911 05 Trenčín
- Company ID (IČO): 57146870
- Tax ID (DIČ): 2122584508
- Email: info@grovtic.com
- Phone: +421 905 211 562
2. What personal data we collect
When you use our website and services, we may collect the following personal data:
- Contact details: first name, last name, email address, phone number — provided through contact forms
- Order details: company name, company ID, project requirements and other information needed to process your order
- Technical data: IP address, browser type, operating system, screen resolution, time of visit — collected automatically through cookies and analytics tools
- Communication data: the content of messages sent via email, the contact form or WhatsApp
3. Purpose of processing personal data
We process your personal data for the following purposes:
- Communication: responding to your questions and requests submitted through contact forms, email or by phone
- Order processing: preparing quotations, entering into contracts and delivering the services you have ordered
- Marketing: sending commercial communications and news (only with your explicit consent)
- Service improvement: analyzing website traffic and behavior in order to optimize the user experience
- Compliance with legal obligations: bookkeeping and tax obligations
4. Legal basis for processing
We process personal data on the following legal bases under Article 6 of the GDPR:
- Consent of the data subject (Art. 6(1)(a) GDPR) — for marketing communications and analytics cookies
- Performance of a contract (Art. 6(1)(b) GDPR) — for order processing and the provision of services
- Legitimate interest of the controller (Art. 6(1)(f) GDPR) — for ensuring the operation of the website, protecting against misuse and communicating directly with existing clients
- Compliance with a legal obligation (Art. 6(1)(c) GDPR) — for accounting and tax purposes
5. Data retention period
We retain your personal data only for as long as is strictly necessary to fulfill the purpose for which it was collected:
- Contact forms: 3 years from the last communication
- Contract data: for the duration of the contract and 5 years after its termination (in accordance with the Commercial Code)
- Accounting records: 10 years (in accordance with the Accounting Act)
- Marketing consent: until consent is withdrawn
- Analytics data: 26 months (Google Analytics)
Once the retention period has elapsed, your data will be securely deleted or anonymized.
6. Cookies
Our website uses cookies — small text files stored in your browser. We use the following types of cookies:
- Essential cookies: ensure the basic functionality of the website (no consent required)
- Analytics cookies (Google Analytics): help us understand how visitors use our site — which pages they visit, how much time they spend on the website and where they came from. This data is anonymized and is used to improve our content and the user experience.
- Marketing cookies (Meta Pixel / Facebook Pixel): allow us to display relevant ads on the Facebook and Instagram social networks. They track conversions and help optimize advertising campaigns.
We use analytics and marketing cookies only with your consent. You can withdraw your consent at any time in your browser settings or by deleting cookies.
7. Third parties and data recipients
We may share your personal data with the following third parties:
- Google LLC (Google Analytics) — website traffic analysis. Google processes data in accordance with its privacy policy.
- Meta Platforms, Inc. (Facebook/Instagram Pixel) — conversion tracking and remarketing. Meta processes data in accordance with its privacy policy.
- Hosting providers — our website is operated on servers that may technically process data transmitted through the website
- Accounting and legal services — to the extent necessary to comply with legal obligations
We do not sell your data to third parties for marketing purposes. The transfer of data to third countries (the USA) in connection with Google and Meta takes place on the basis of standard contractual clauses approved by the European Commission.
8. Rights of the data subject
As a data subject, you have the following rights under the GDPR:
- Right of access — you have the right to obtain confirmation as to whether your personal data is being processed and, if so, to access that data
- Right to rectification — you have the right to request the correction of inaccurate or incomplete personal data
- Right to erasure ("right to be forgotten") — you have the right to request the deletion of your personal data when it is no longer necessary for the purpose for which it was collected
- Right to restriction of processing — you have the right to request that the processing of your data be restricted in certain cases
- Right to data portability — you have the right to receive your personal data in a structured, commonly used and machine-readable format
- Right to object — you have the right to object to the processing of data based on legitimate interest or for direct marketing purposes
- Right to withdraw consent — where processing is based on consent, you have the right to withdraw that consent at any time
- Right to lodge a complaint — you have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk)
9. How to exercise your rights
You can exercise your rights by contacting the controller:
- Email: info@grovtic.com
- Phone: +421 905 211 562
- By post: Syki Group s.r.o., Veľkomoravská 2162/16B, 911 05 Trenčín
We will respond to your request without undue delay, no later than 30 days from its receipt.
10. Data security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure or destruction. These measures include:
- Encryption of data transmission (SSL/TLS)
- Restricted access to personal data, limited to authorized persons only
- Regular backups and system updates
11. Changes to this Privacy Policy
We may update this policy from time to time. We will inform you of any significant changes through our website. We recommend that you review this page regularly.
See also our General Terms and Conditions.