Updated: August 2026.
On this page we have gathered everything that happens to your data on the site: which forms collect what, which external services see something, how long all of it is kept and how to opt out of it. We wrote it in plain language — it is meant to be read by people, not by lawyers.
This policy covers the site kompas.guide/sk — the KOMPAS section for Ukrainians in Slovakia (in Ukrainian, Russian and English). The old domain kompas-slovakia.com now redirects here. The Czech section kompas.guide/cz has its own separate policy: it has a different set of services and its own supervisory authorities.
1. Who is responsible for your data
The controller is the one who decides why and how data is processed. Here it is a self-employed individual:
- Name: Skoblei Vladyslav (OSVČ, Czech Republic)
- IČO: 23409797
- DIČ: 0009231497
- Address: Uralská 689/7, 160 00 Praha 6 – Bubeneč, Česká republika
- E-mail: [email protected]
- Languages for enquiries: українська, русский, čeština, slovenčina, English
This is the same mailbox we read ourselves — not an auto-responder and not a bot. The full imprint and the points of contact for public authorities are on the Contacts page.
No Data Protection Officer (DPO) has been appointed. Processing data is not our core activity, we do not carry out large-scale systematic monitoring of people and we do not process special categories of data on a large scale — so there are no grounds under Article 37 GDPR for a mandatory appointment. For any question about data, write to the address above.
2. What we collect — in brief
Data reaches us in three ways:
- You send it yourself — you fill in a form, leave a review, register an account, write us a message.
- It arises technically — any visit to any website leaves an IP address, a browser type and the time of the request. Part of this we use for security, part — only with your consent, for statistics.
- We take it from public sources — this applies only to the specialists directory, and it has its own Section 4.
We do not send e-mail newsletters, do not sell data, do not show Google AdSense advertising and do not ask for payment details — there is no payment on the site.
3. Why we process data — situation by situation
You are simply reading the site
- Data: IP address, device and browser type, the page you came from, the time of the request, country by IP.
- Why: to deliver the page, to cope with the load, to fend off attacks and bots, to work out what happened if something broke.
- Legal basis: our legitimate interest (Art. 6(1)(f) GDPR). The interest, put into words: to keep the site available and protected from abuse. Without basic server logs this is impossible.
- Retention: technical error logs — 90 days. Network logs of attack protection — on Cloudflare's side, under their retention periods.
Cookies and your choice
On your first visit you see a banner with three categories: necessary (always on), analytics and marketing. The last two toggles are off by default — until you switch them on yourself, no third-party script is loaded.
- Data: your choice of categories is stored in the browser's memory (key
kompas_cookie_consent) plus a technical cookie marker. Separately, on the server, we record the fact of the choice: date and time, which categories, banner version, browser string. The IP address is not stored. - Why: so as not to ask you every time — and to be able to prove that consent was really given (Art. 7(1) GDPR requires this of us, not of you).
- Legal basis: for the record of the choice itself — legitimate interest to demonstrate compliance with the law; for whatever is switched on by that choice — your consent (Art. 6(1)(a)).
- Retention: the choice lasts 365 days if you allowed something, and 180 days if you refused everything — after that the banner asks again. The server-side consent log is kept while the consent is valid and for 3 more years after it is withdrawn or expires — as evidence of consent.
- To change or withdraw: the “Change cookie settings” button in the footer of every page and on the Cookies page. Withdrawal takes effect for the future and does not make unlawful what happened before it.
Traffic analytics — only with your consent
- Services: Google Analytics 4 and Ahrefs Analytics.
- Data: pages viewed, time spent on them, device type, approximate city by IP, identifiers in cookies (
_ga,_ga_*). - Why: to understand which materials people read and which they do not, and what is broken on the site.
- Legal basis: consent to the “analytics” category (Art. 6(1)(a)). Without consent the scripts are not loaded at all.
- Retention: in Google Analytics — 14 months; the
_gacookie — up to 2 years or until you delete it in your browser.
Marketing pixels — only with your consent
- Service: Meta Pixel (Facebook / Instagram).
- Data: the fact of a visit and of page views, an identifier in the
_fbpcookie. - Why: to assess whether our advertising on social media worked, and to show ads to the people who may find them useful.
- Legal basis: consent to the “marketing” category (Art. 6(1)(a)).
- Retention: the
_fbpcookie — about 90 days; after that — under Meta's policy. - To opt out: switch the category off in the cookie settings; in addition — in the advertising settings of your Meta account.
Behavioural statistics of sections — only with your consent
- Data: an event such as “opened a school card”, “clicked show contact”, “expanded the gallery” — tied to a random device identifier stored in your browser's memory.
- Why: to show schools and agencies anonymised statistics of interest in their cards.
- Legal basis: consent to analytics (Art. 6(1)(a)). Without consent the identifier is not created and events are not recorded.
- Retention: 14 months.
View and click counters
- Data: the fact that an article, a news item, an event or a glossary term was viewed, or that a contact in a listing was clicked. So that one person is not counted ten times, we take an irreversible hash of the IP address, a secret key and the current date. The IP address itself is not stored anywhere, and the key changes every day — that is, yesterday's hashes cannot be matched against today's.
- Why: to show “how many times it was read” and to understand what is needed on the site.
- Legal basis: legitimate interest to have honest statistics about our own content without identifying the reader (Art. 6(1)(f)).
- Retention: 14 months.
Personal account
- Data: e-mail; a personal or company name; optionally — phone, messengers, links to social media, website, profile photo. Sign-in — via Google or with an e-mail and a password. We do not see your password: it is stored as a hash.
- Why: to let you sign in, edit your own listings and cards, and get in touch with you about them.
- Legal basis: performance of a contract with you — the use of the account (Art. 6(1)(b)).
- If you sign in via Google: Google tells us your address, name and profile photo. We do not receive your password and we have no access to your mailbox.
- Retention: as long as the account exists. In your account there is a “Delete account” button — it works immediately: the profile is wiped, the account record and all sessions are deleted. Directory cards that you claimed as yours do not disappear — they are unpublished and go back into the moderation queue with no link to you.
Requests and enquiries through forms
- Data: name, means of contact (e-mail, phone or a messenger handle), the text of the enquiry, the page it was sent from, and the IP address.
- Why: to reply to you and to pass the enquiry on to whoever it concerns (a school, for example).
- Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b)); storing the IP address — legitimate interest to investigate spam and abuse of the form (Art. 6(1)(f)).
- Where it goes: a notification about a new request arrives in the editorial team's working chat on Telegram. Your IP address is not passed on in that message — it stays only in our database.
- Retention: 24 months.
Housing listings: the enquiry goes to the realtor
If you leave an enquiry under a particular housing listing, we forward it to the author of the listing on Telegram — otherwise they will not be able to reply to you. This means that your contact details are received by another person or company, and from then on they handle them as a separate controller, under their own policy. We pass on only what you wrote in the form. If you do not want anyone except the editorial team to see your contact details — do not use the form under the listing, write to us directly.
Reviews of schools and agencies
- Data from you: a name or signature, the text of the review, a rating; optionally — an e-mail or Telegram for getting back to you.
- Technical data: together with the review we store the IP address, the browser string, the source page, the country by IP, and also device parameters — screen size, time zone, system language, platform.
- Why the technical data: to filter out fake ratings. Paid-for reviews are the main problem of any directory, and without these signals a dozen “different” reviews from one device are indistinguishable from a dozen genuine ones.
- Legal basis: publication of the review itself — your consent, which you give by clicking “send” (Art. 6(1)(a)); the technical signals — legitimate interest to detect manipulation and protect the honesty of the rating (Art. 6(1)(f)).
- Who sees this: publicly only your signature, rating and text are visible. E-mail, Telegram and the technical data are available to the editorial team only.
- Retention: as long as the review is published. Ask us — and we will delete it together with the metadata.
Comments under articles
- Data: a name or nickname, the text of the comment, optionally — an e-mail (it is not shown publicly).
- Legal basis: your consent to publication (Art. 6(1)(a)).
- Retention: as long as the comment is published; we delete it at the author's request or for a breach of the rules.
- When you comment, the IP address is used only as a temporary key for limiting the rate of requests and is not stored.
Complaints about job listings
- Data: the reason for the complaint, a comment, optionally — an e-mail, and also the IP address.
- Why: to check the listing and take it down if the complaint is confirmed.
- Legal basis: legitimate interest not to let fraudsters and intermediaries who charge a fee use our site (Art. 6(1)(f)).
- Retention: 12 months.
Notices about content (complaints about illegal content and reports of outdated materials)
- Data: your name and e-mail, a link to the material and a description of the problem.
- Why: to examine the complaint about the material and inform you of the decision — this is required by Art. 16 of Regulation (EU) 2022/2065 (DSA).
- Legal basis: compliance with a legal obligation (Art. 6(1)(c)).
- Retention: 12 months.
The translator on the site
The “Translator” page works through the external service MyMemory (Translated srl, Italy). The text you paste into the field leaves our server — we neither store it nor log it, but we do send it to a third party for translation, and what that party does with it next depends on their terms.
- Legal basis: performance of the service you requested (Art. 6(1)(b)).
- Retention on our side: zero — neither the source text nor the translation reaches the database.
- A warning worth taking seriously: do not paste passport details, medical certificates, tenancy agreements or letters from the úrad that contain other people's data there. Documents need a sworn translation, not a machine one.
Your messages and enquiries
When you write to us by e-mail or contact us about your rights, we process what is in the message: the address, the name, the content. The legal basis is legitimate interest to answer the enquiry, and for requests about rights — a legal obligation (Art. 6(1)(c)). We keep the correspondence for as long as it takes to reply and to confirm that we did.
4. The specialists directory: data we did not receive from you
The specialists directory contains cards collected from public sources — public Telegram channels and chats, open pages on Facebook and Instagram, industry directories and the specialists' own websites. That is, we did not receive this data from the person it concerns. Article 14 GDPR requires this to be explained separately — we do that here.
- Categories of data: a personal or company name, profession or specialisation, city, languages of service, a public business contact (phone, messenger, a link to a profile or website), a description of services.
- Sources: the public resources listed above; some cards were created by the specialists themselves, some were sent in by readers. Technically, we collect public pages through the Apify service.
- Legal basis: legitimate interest (Art. 6(1)(f)). We name it plainly: to give newly arrived people a way to find a specialist who speaks their language, instead of searching blindly through chats. We weighed this against the interests of the specialists themselves and limited ourselves to business contacts, which they publish for clients anyway.
- What we deliberately do not do: we do not publish home addresses or private phone numbers, we do not add photographs of people without their permission, we do not collect data about the specialists' clients.
- Who we pass it to: no one. The cards are public on the site, but we neither sell nor hand over the database.
- Retention: as long as the card is published or until you ask us to take it down.
Your rights here are wider than usual. If you have found yourself in the directory:
- every card has a “This is my card” button — through it you can claim the card, correct the data or ask us to take it down altogether;
- we do not ask for reasons. A request to take a card down is carried out within 72 hours;
- you have the right to object to processing (Art. 21 GDPR) at any moment — and in a dispute about a card in the directory we do not argue.
The directory section is not open to the public yet, but the data in it already exists — which is exactly why this part of the policy is written now and not “when we launch”.
5. Who we pass data to
We do not sell data and do not pass it to “marketing partners”. The list below is everyone who technically sees something, and exactly what for.
| Who | What they see and why | Where |
|---|---|---|
| Cloudflare, Inc. | All site traffic passes through their network: IP address, request data. Protection from attacks, bot filtering, faster loading. | Global network; requests from Europe are usually served by European nodes |
| Our own server | This is where the site and the database physically sit (Supabase, deployed by us ourselves, not the cloud service). | Netherlands, EU |
| Google Ireland Ltd. / Google LLC | Google Analytics 4 — only with consent to analytics. Sign-in via Google — only if you used it. Google Maps — maps on pages with addresses. | EU / USA |
| Meta Platforms Ireland Ltd. | Meta Pixel — only with consent to marketing. | EU / USA |
| Ahrefs Pte. Ltd. | Ahrefs Analytics — anonymised traffic statistics, only with consent to analytics. | Outside the EEA (Singapore) |
| Telegram | Notifications to the editorial team about new requests and complaints. For housing listings — forwarding the enquiry to the author of the listing. | Outside the EEA |
| The author of the listing (realtor, agency) | Your name and contact details from the enquiry under their listing. From then on they are a separate controller. | Slovakia / EU |
| Translated srl (MyMemory) | The text you entered into the translator on the site. | Italy, EU (with the possible involvement of subcontractors) |
| OpenAI, OpenRouter, DeepL SE | Automatic translation of the site content into three languages — including the texts of listings and the descriptions in profiles that you publish. | EU / USA |
| ElevenLabs | Voicing of glossary terms. Receives no personal data. | USA |
| Apify | Technical collection of publicly available pages for the directories. | Czech Republic, EU |
| Public authorities | Only where the law requires it and on a lawful basis. | SK / CZ / EU |
6. Does data leave the EU
The site and the database sit in the European Union. But some of the services in the list above are American or global, so certain data may be processed outside the European Economic Area.
For such transfers we rely on an adequacy decision of the European Commission — and where it does not apply or has ceased to be valid, on the Commission's Standard Contractual Clauses (SCC) together with additional technical measures. This wording is deliberately not tied to one particular framework: adequacy decisions are reviewed by the courts from time to time, and the set of safeguards you get should not change because of that.
7. How long we keep data
These periods are not declarations — an automatic cleanup of the database enforces them every day. Whatever is past its period is deleted, not “archived”.
| What | How long |
|---|---|
| Requests and enquiries from forms | 24 months |
| Complaints about job listings | 12 months |
| Notices about content and outdated materials | 12 months |
| Behavioural statistics events (schools, directory) | 14 months |
| View counters (articles, news, events, glossary) | 14 months |
| Clicks on contacts in listings | 14 months |
| Technical error logs | 90 days |
| Log of editorial actions in the admin panel | 24 months |
| Cookie consent log | kept while the consent is valid and for 3 more years after it is withdrawn or expires — as evidence of consent (Art. 7(1) GDPR) |
| Account and profile | until you delete it |
| Published reviews, comments, listings, cards | as long as they are published or until you ask us to take them down |
Database backups are kept for up to 30 days — that is, deleted data disappears from the backups for good within that period.
8. Your rights
All these rights are free of charge. We reply within 30 days; if a request is complex, we may extend the period by a further two months, but we are obliged to tell you about it and explain why.
- Access (Art. 15) — to find out whether we hold your data, exactly what data and what we do with it, and to receive a copy of it.
- Rectification (Art. 16) — to correct a mistake or complete incomplete data.
- Erasure (Art. 17) — the “right to be forgotten”. For an account — the button in your account, it works immediately. For everything else — a message to us.
- Restriction of processing (Art. 18) — to ask us to “put it on pause” while we sort out a disputed question.
- Portability (Art. 20) — to receive the data you gave us in a machine-readable format.
- Objection (Art. 21) — to object to processing based on legitimate interest: the directory, statistics, security. You can object to direct marketing at any time and without giving reasons.
- Withdrawal of consent (Art. 7(3)) — at any moment and just as easily as you gave it: the “Change cookie settings” button in the site footer. Withdrawal does not make unlawful what already happened before it.
- Not to be subject to an automated decision (Art. 22) — see Section 11.
To use any of them, write to [email protected]. We may ask for clarification if it is impossible to tell from the message whose data is meant — but we will not demand copies of documents “just in case”.
9. Where to complain
If you feel that we are handling your data wrongly, write to us first — most questions are resolved by a single message. But you are not obliged to come to us first and you may lodge a complaint with a supervisory authority straight away.
Article 77 GDPR allows you to choose the authority of the country where you live, where you work or where the alleged infringement took place. Our audience lives in Slovakia and the operator is registered in the Czech Republic — so both are suitable:
- Slovakia: Úrad na ochranu osobných údajov Slovenskej republiky, Galvaniho Business Centrum II, Galvaniho 7/B, Bratislava. E-mail: [email protected], website: dataprotection.gov.sk
- Czech Republic: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7. E-mail: [email protected], website: uoou.gov.cz
10. Do you have to give your data
No. You can read the site without telling us anything about yourself at all: every form is voluntary, registration is not required, analytics and marketing can be refused with a single button — the site works exactly the same either way.
But some actions are impossible without data, and this is not a punishment, it is physics: without a name and a contact we cannot answer your request; without an e-mail there is no account, because the address is your login; without the text of a complaint it is impossible to check a listing. If you do not provide this data, we simply will not be able to provide the service in question — there will be no other consequences.
11. Automated decisions and profiling
We do not take decisions about you automatically — decisions that would have legal effects or significantly affect you (Art. 22 GDPR). No one gains or loses access, status or a service because of a decision made by an algorithm.
Artificial intelligence on the site works with texts, not with people: it translates materials into three languages, sorts articles into topics and helps the editorial team prepare content. Before publication, materials are read and checked by a live person — the editorial team, which is also responsible for them. Moderation of reviews, comments and listings is likewise a decision made by a human, not by a machine.
12. Children
The site is intended for adults. We do not knowingly collect the data of persons under 16 years of age and do not offer them services. If it turns out that the data of such a person has reached us without parental consent, we will delete it as soon as we find out. If you are a parent and you see that the site holds your child's data — write to us, we will remove it without unnecessary formalities.
13. How we protect data
- All connections go over HTTPS (TLS) only, without exceptions.
- The site and the database are on our own server in the EU; access to the database is held by a limited circle of people and only through secure keys.
- Personal data from forms and reviews is not accessible to the site's public key — only the server side of the admin panel reads it.
- Passwords are stored as irreversible hashes, IP addresses in the counters — as salted hashes with a daily key rotation.
- Backups are made every day and stored separately from the main server.
- Third-party scripts are not loaded until you have given consent.
One hundred per cent security does not exist on the internet, and promising it would be untrue. If a breach occurs that threatens your rights, we will notify the supervisory authority within 72 hours, and you — without undue delay, as required by Art. 33–34 GDPR.
14. Changes to this policy
The site changes, and the policy will change along with it. The current version is always on this page, with the update date at the top. If the changes are significant — a new service appears that sees your data, or a legal basis for processing changes — we will announce it visibly on the site, and not by quietly editing the text. If a change concerns something you gave consent to, we will ask for consent again.
Questions, comments, a request about your data: [email protected]. Write in Ukrainian, Russian, Czech, Slovak or English — we will reply.