Legal
Privacy notice
How UniqTec s.r.o. handles personal data on trustink.io, in the tenant portal and on the signing pages.
Draft: This document is pending legal review. It shows the structure and intent of our terms and will change before it takes effect.
Who is responsible
UniqTec s.r.o., Slovakia ([registered office and company ID to be added]), operates TrustInk. We are the controller for the data described under “Visitors, contacts and customers”. For the documents and participant data our customers send through TrustInk, the customer is the controller and we process the data on its behalf under the data processing agreement.
Contact for privacy questions: privacy@trustink.io.
Visitors, contacts and customers
| What | Why | Legal basis |
|---|---|---|
| Technical data of your visit (IP address, browser, pages requested), kept in server logs | Operating and securing the website | Legitimate interest, Art. 6(1)(f) GDPR |
| What you send through the contact form (name, email, company, message) | Answering you | Steps before a contract or legitimate interest, Art. 6(1)(b) and (f) |
| Account data of customers (names and email addresses of users, company details, billing data) | Providing the service and billing it | Contract, Art. 6(1)(b); legal obligations for invoices, Art. 6(1)(c) |
trustink.io uses no analytics and no tracking cookies. The website stores your theme choice (light or dark) in your browser’s local storage; it never leaves your device.
Participants who sign
When an organisation asks you to sign a document through TrustInk, that organisation decides why and how your data is used. We process on its behalf: your name, email address, phone number if a code is sent by SMS, the document, your drawn signature, the time and the technical data of each step (IP address, browser), and the certificate issued to you for that signing. This data goes into the signed document and the sealed evidence summary that proves the signing. Questions about it are best directed to the organisation that sent you the document; we will pass on requests we receive.
Who receives data
We use carefully chosen service providers (sub-processors), listed with their purpose on our trust page. The service is hosted on Amazon Web Services in the EU (Ireland, eu-west-1). A timestamp authority receives only a document fingerprint, never the document or personal data.
Transfers outside the EU
We store and process data in the EU. Where a provider may access data from outside the EU, the transfer is covered by the European Commission’s standard contractual clauses or an adequacy decision. [To be confirmed per provider with counsel.]
How long we keep data
- Server logs: [period to be set, for example 90 days].
- Contact requests: as long as needed to answer and follow up, at most [period to be set].
- Customer account data: for the duration of the contract, and invoices as long as tax law requires.
- Documents and participant data: for the retention period the customer’s plan and settings allow, then deleted.
Your rights
You have the right to access, rectify and erase your data, to restrict or object to its processing, and to data portability, as the GDPR provides. Write to privacy@trustink.io. You may also lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), or with the supervisory authority where you live.
Changes
This notice is versioned; the current version is shown at the top of this page and published at /legal/versions.json.
Questions about this document? Contact us ·Current versions as JSON