What this policy says, in plain terms
Legal basis
GDPR · contract · consent
Retention
5 years (statutory invoices)
Recipients
Payments & accounting
Your rights
Access · delete · port
Security
HTTPS · encrypted DB
Cookies
Essential only by default
EasyCar takes a deliberately minimal approach to personal data. We collect what we need to take your booking, deliver the car and meet our legal obligations — nothing more. This page explains exactly what we hold, why we hold it, how long for, who else sees it and what you can ask us to do with it.
The policy follows the General Data Protection Regulation (EU 2016/679) and Slovak Act 18/2018 on the protection of personal data.
Data controller
The controller of your personal data is INVETIX s.r.o., the legal entity operating EasyCar:
- Registered office: Jiřího Wolkera 466/14, 058 01 Poprad, Slovakia
- Company ID (IČO): 51 666 901
- Tax ID (DIČ): 2120744428
- Contact email: hello@easycar.sk
EasyCar does not appoint a separate Data Protection Officer; the company itself is the single point of contact for all privacy questions and rights requests at the email above.
What we collect
We collect three categories of information:
- Reservation data — full name, phone, email, pick-up and drop-off details, flight number (where supplied), choice of vehicle, message text and any optional extras you select on the booking form.
- Identity data captured at pick-up — the driving licence number, passport or ID number, date of birth and signature on the rental agreement. This is kept on the paper / PDF contract only, not in the website database.
- Technical metadata — IP address, browser user agent, referrer, approximate region, and timestamps of your visit. This is collected for fraud prevention and to keep the site running. It is never linked to your name in our analytics layer.
We do not collect special category data (health, religion, political views), we do not buy lists, and we do not run hidden trackers.
Why we collect it
Each piece of data has one specific job:
- Process your booking — confirm availability, prepare the car, deliver it on time.
- Issue invoices and rental agreements as required by Slovak accounting law.
- Prevent fraud and protect the fleet — flag duplicate IPs, refuse bookings from blocked drivers, identify damage claims.
- Improve the service — aggregated analytics on which routes book well and which articles get read.
- Send service email — booking confirmations, pick-up reminders, change-of-plan messages.
- Send marketing — only if you have given explicit, separate consent at booking. We never assume consent.
Legal basis
Under GDPR we rely on the following grounds:
- Performance of a contract (Art. 6(1)(b)) — everything needed to actually rent you a car.
- Legal obligation (Art. 6(1)(c)) — storing invoices and rental agreements for the statutory period.
- Legitimate interest (Art. 6(1)(f)) — site security, fraud prevention, and protecting our vehicles.
- Consent (Art. 6(1)(a)) — only for marketing emails, non-essential cookies, and customer testimonials we publish with your photo.
How long we keep it
Retention is tied to purpose:
- Invoices and rental agreements — 5 years, as required by Slovak accounting and tax law.
- Reservation records in the database — 24 months from the rental end date, then archived in anonymised form.
- Booking enquiries that never converted — 12 months, then deleted.
- Technical logs (IP, user agent) — 90 days.
- Marketing list — until you unsubscribe, which you can do in one click from every email we send.
Recipients
Your data is shared only with carefully selected processors that need it to deliver the service:
- Payment processors — only the minimum required to settle the deposit hold and any final charge. EasyCar never stores raw card numbers.
- INVETIX accounting — the external accountant who keeps INVETIX s.r.o. compliant with Slovak tax law.
- Email delivery — a transactional email provider that handles booking confirmations.
- Hosting — an EU-based hosting partner where the website and database physically run.
None of these recipients are permitted to use your data for their own purposes. No data is transferred outside the European Economic Area without a valid GDPR transfer mechanism (Standard Contractual Clauses).
Your rights
Under GDPR you have the right to:
- Access — ask for a copy of everything we hold about you.
- Rectification — correct anything that is wrong or out of date.
- Erasure (“right to be forgotten”) — delete your data, unless we have a legal duty to keep it (e.g. invoices for the statutory 5 years).
- Portability — receive your data in a structured, machine-readable format.
- Restriction and objection — pause our processing or object to specific uses, especially marketing.
- Withdraw consent at any time for anything we do on the basis of consent.
- Complain to the Slovak supervisory authority (Úrad na ochranu osobných údajov SR) if you believe we have not handled your data correctly.
Send any rights request to hello@easycar.sk — we respond within 30 days at the latest.
Security
The site is served exclusively over HTTPS with modern TLS. Production databases are encrypted at rest, backed up nightly, and accessible only from a small number of EasyCar accounts protected by two-factor authentication.
If a personal data breach affecting EasyCar customers ever occurs, we will notify the Slovak supervisory authority within 72 hours and contact affected users directly when the breach is likely to result in a high risk to them.
Changes & contact
EasyCar may update this policy to reflect changes in the service or in the law. The current version always lives at easycar.sk/privacy with the last-updated date at the top.
Material changes are announced by email to customers with active bookings at least 14 days before they take effect.
Privacy questions and rights requests: hello@easycar.sk.
Data controller
INVETIX s.r.o.
Jiřího Wolkera 466/14, 058 01 Poprad, Slovakia
IČO: 51 666 901 · DIČ: 2120744428
Phone: +421 907 311 206
Email: hello@easycar.sk
Web: www.easycar.sk