Privacy Policy
The company Web security s.r.o., ID No.: 06927351, with its registered office at Nové sady 988/2, 602 00 Brno, Czech Republic, registered in the Commercial Register maintained by the Regional Court in Brno, Section C, File 105154, contact email: info@sslmentor.com (hereinafter referred to as the "company"), issues this Privacy Policy and declares that it provides its services in accordance with applicable legislation and handles customers' personal data in compliance with applicable legal regulations.
Through this document, we provide customers with information regarding the processing of their personal data, related rights, and other obligations pertaining to the www.sslmentor.com project. This document may be revised and updated as necessary.
General Information
We consider all personal data of users and visitors to be confidential, and it is handled in accordance with Regulation (EU) 2016/679, known as GDPR (General Data Protection Regulation).
In the processing of customers' personal data, the company acts as a data controller within the meaning of Article 4(7) of the GDPR. If, in individual cases, it processes personal data on behalf of another controller, it does so solely on the basis of a relevant data processing agreement.
We process personal data both manually and automatically. For these operations, we maintain records of processing activities involving personal data.
What Personal Data Do We Collect?
We only process personal data to the extent necessary to fulfill a specific purpose, applying the data minimization principle pursuant to Article 5 of the GDPR.
Providing personal data marked as mandatory is a prerequisite for entering into and performing a contract. Without providing this data, it is not possible to create a customer account, ensure the issuance of ordered certificates, or provide other ordered services.
Orders of SSL/TLS, CODE, and S/MIME Certificates
The collection and processing of personal data to secure certificates are necessary for the performance of a contract. The processed data may vary depending on the type of certificate and are required based on the CA/Browser Forum specifications (cabforum.org). DV and OV certificates are governed by the Baseline Requirements documents, while EV certificates are governed by the Extended Validation Guidelines. These documents standardize the issuance of SSL certificates, describing the requirements for certification authorities and applicants.
Customer Account
When creating a customer account, we only require: an email address and billing details. We must process these personal data for the purpose of customer identification, authorization, and the operation of the customer account, without which it is not possible to use our services. Furthermore, we log the access IP address.
Data within the customer account can be modified or updated at any time.
Legal Obligations
We also process personal data to fulfill legal obligations; pursuant to the Accounting Act and other legal regulations, particularly in the area of taxation, we retain documents (in electronic or paper form) containing personal data for the period prescribed by law.
Other Purposes
We also use customers' personal data for marketing and the promotion of our services. We never provide personal data to third parties for marketing purposes. We process the personal data consisting of the email address for the purpose of sending electronic commercial communications regarding similar products of our company, without consent in accordance with legal regulations, as these are existing customers of our company. The customer can refuse the sending of these commercial communications at any time in the settings of their administrative account.
How Long Do We Retain Personal Data?
We retain your data only for the time strictly necessary:
- Performance of contract and customer account: We retain personal data for the duration of the contractual relationship and the existence of the customer account. An account is considered inactive if no order or login has occurred for a period of 5 years. After this period expires, we anonymize the identification data so that it can no longer be associated with a specific individual.
- Legal obligations (accounting and taxes): We retain documents for the period specified by law (generally 10 years from the end of the accounting period).
- Legitimate interest (marketing): We process the email address for sending commercial communications for a period of 3 years from your last purchase, or until you unsubscribe.
Is Personal Data Provided to Third Parties?
In the event that we provide the ordered services or a part thereof through other entities (e.g., certification authority, contractual partner), we will provide personal data to these third parties only to the extent strictly necessary for the provision of the ordered service. We are authorized to handle personal data in this manner without consent, as we would otherwise be unable to fulfill the contract and provide the requested service.
For the purpose of providing services related to securing SSL/TLS, CODE, and S/MIME certificates, personal data may be transferred to certification authorities and contractual partners based in the European Union, the United States of America, and other countries, if necessary for the provision of the ordered service. The transferred personal data may include, in particular, the first name, surname, address, email address, and telephone number of the natural person. In the case of transferring personal data to the United States of America, data is transferred to entities that ensure an adequate level of personal data protection, in particular on the basis of the EU–US Data Privacy Framework or standard contractual clauses. The transfer of personal data outside the European Union takes place only if it is necessary for the issuance of the ordered certificate or the provision of the ordered service.
Cookies
Cookies help us develop our services. We use them, for example, to store customer settings, track the number of visitors to the page and their behavior. Furthermore, for example, to identify the user's device, optimize our website, provide or offer individualized services, and for third-party services.
Consent can be changed at any time via the "Cookie Settings" link available in the footer of all website pages.
Cookies
- Necessary cookies – required for the proper functioning of the website; their use does not require consent.
- Preferential
- Statistical
- Marketing
We store preference, analytical, and marketing cookies only based on your consent, which you can withdraw at any time. The validity of cookies is standardly set to 1 year.
If the user configures their web browser to block all cookies, it is possible that some of our services may be partially dysfunctional.
List of used services: Google Analytics (GA4), Google Ads, Meta Pixel (Meta Platforms Ireland Ltd.), Seznam Sklik. When using Google and Meta services, personal data may be transferred to the USA. The transfer takes place on the basis of the EU–US Data Privacy Framework or standard contractual clauses (SCC). The providers are certified under the DPF.
Who Has Access to Personal Data?
Within our company, access to personal data is restricted solely to persons for whom it is strictly required to achieve the purpose for which the personal data is processed.
Employees with access to personal data are properly trained in its protection and are bound by confidentiality obligations.
Where Do We Store Personal Data?
Users' personal data is stored on servers located within the territory of the Czech Republic. To secure our services, we choose providers capable of guaranteeing the security of their services and who comply with personal data protection principles. We select suppliers with server locations in data centers that meet at least the TIER III standard or a comparable level of availability.
We protect personal data using TLS 1.3 encryption, regular system updates, and controlled access.
How Is Personal Data Secured?
We protect users' personal data using modern standards. Communication between our web projects and the user is secured via SSL/TLS encryption.
For administration access, customer passwords are stored solely in the form of one-way cryptographic hashes and are never kept in plain text.
How Can Editing or Erasure of Personal Data Be Requested?
After logging into the customer account, the user can edit their personal data. If the user wishes to completely delete all personal data and records we maintain, it is necessary to contact customer support. Data whose retention is required by legal regulation or the legitimate interest of the controller cannot be removed before the expiration of the relevant statutory period.
Deleting a customer account is an irreversible process and is performed only upon the active request of the user.
Automated Decision-Making and Profiling
When processing personal data, we do not perform automated individual decision-making or profiling within the meaning of Article 22 of the GDPR.
Customer Rights Related to Personal Data Protection
In connection with personal data protection, the customer has the right to:
- obtain confirmation as to whether or not personal data concerning them is being processed
- obtain information about the purposes of processing
- the erasure of personal data concerning them, unless we are able to demonstrate legitimate grounds for further processing of such personal data
- the right to object to the processing of personal data on the grounds of our company's legitimate interest or against the dissemination of commercial communications
- refuse the processing of personal data for the purpose of sending commercial communications
- withdraw consent to the processing of personal data at any time, if our company processes it based on consent; however, such withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal
- the right to restriction of processing – if you believe that we process inaccurate data or that the processing is unlawful, but you do not want the data to be deleted directly
- the right to data portability – you have the right to receive your personal data in a structured, commonly used, and machine-readable format and transmit those data to another controller
- the right to lodge a complaint with a supervisory authority – if you believe that we handle your data in violation of the law, you have the right to lodge a complaint with the Office for Personal Data Protection (https://uoou.gov.cz/kontakt)
We will process your request without undue delay, at the latest within 30 days. In complex cases, we may extend this period by an additional 60 days, of which we will inform you.
Changes
This Privacy Policy may be regularly revised.
Effective from: June 30, 2026.
›› If you have any questions regarding this policy, please do not hesitate to contact us for clarification. You may also contact us at any time to exercise your right to erasure.
