1. Data controller
The controller determines why and how personal data submitted through the Executive Fleet website and reservation service are processed.
- Controller
- Executive fleet s. r. o.
- Company ID
- 51 135 515
- Registered office
- Fialová 4B, 851 07 Bratislava - mestská časť Petržalka, Slovenská republika
- Register
- Obchodný register Mestského súdu Bratislava III, oddiel: Sro, vložka č. 178488/B
- Privacy contact
- sivak.filip@gmail.com · +421 905 616 848
2. Personal data we process
Reservation and communication data
- name and surname,
- email address and telephone number,
- selected vehicle, pickup and return dates and reservation reference,
- price snapshot, deposit and reservation status,
- subsequent communication, contract, handover and incident data where applicable.
Technical and security data
Cloudflare Pages and Turnstile may process the IP address, request time, browser and device information, visited URL, security signals and technical logs to deliver and protect the website. The reservation endpoint applies rate limiting and bot protection. The Turnstile token is verified for the request and is not stored in the reservation record by the application.
3. Purposes and legal bases
- Reservation, pre-contractual communication and rental agreement: steps requested before entering into a contract and performance of the contract.
- Accounting, tax and legal obligations: compliance with legal obligations.
- Protection of vehicles, claims and network security: legitimate interests in preventing fraud, proving claims and operating the service securely.
The mandatory reservation checkbox records that the customer has reviewed the Terms and this information. Contract processing is not based on consent that could be withdrawn while the service still requires the data.
The application does not use automated decision-making or profiling.
4. Recipients and processors
- authorised Executive Fleet personnel handling reservations and administration,
- Supabase for database and authentication infrastructure,
- Cloudflare for hosting, content delivery, Turnstile and security,
- email, telecommunication, accounting, legal and insurance providers where required,
- public authorities where disclosure is required by law.
5. International transfers
Some infrastructure providers may process data outside the European Economic Area. Where required, transfers must rely on an adequacy decision, standard contractual clauses or another lawful safeguard.
Supabase project region: AWS eu-west-1 (West EU – Ireland / Západná EÚ – Írsko). Where Supabase processing involves a transfer outside the EEA, the applicable Supabase Data Processing Addendum provides transfer safeguards including the EU Standard Contractual Clauses where required.
6. Retention periods
- Accounting documents
- 10 rokov nasledujúcich po roku, ktorého sa účtovné doklady týkajú / 10 years following the year to which the accounting records relate.
Data may be retained longer only where required by law or necessary to establish, exercise or defend legal claims.
7. Your rights
Depending on the circumstances, you may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interests. You may also lodge a complaint with the supervisory authority.
Send requests to sivak.filip@gmail.com. We may reasonably verify your identity before responding.
8. Required data and consequences
Providing name, email, telephone number, rental dates and the selected vehicle is necessary to create and manage an online reservation. Without these data, the operator cannot complete the reservation. Other information is requested only where required for handover, legal obligations, insurance or a specific incident.
9. Cookies and local storage
The public website does not use advertising pixels or a marketing analytics script. Session storage may temporarily remember the scroll position for a stable page refresh. Cloudflare Turnstile may use strictly necessary browser storage or cookies to distinguish legitimate users from automated traffic. The separate administration uses Supabase authentication storage for signed-in authorised staff.
10. Security and changes
The service uses access controls, row-level database security, encrypted HTTPS transport, bot protection and restricted server-side credentials. No measure can provide absolute security, but controls are reviewed according to the nature and risk of processing.
This information will be updated when purposes, providers, retention periods or legal requirements change. The current version is always published at this URL.