PRIVACY POLICY 

 Version 1.0 (Initial Version) 
Effective Date: 24 September 2026 

1. Introduction 

The Controller is committed to the protection of personal data and the privacy of visitors to this website. This Privacy Policy provides information on the processing of personal data when visiting the website, in particular regarding the categories of personal data processed, the purposes and legal bases of processing, recipients of personal data, retention periods, and the rights of data subjects. 

The website serves an informational and promotional purpose. It does not contain a contact form, newsletter subscription, user registration, or functionality enabling users to directly submit CVs, job applications, or other employment-related requests. 

2. Controller 

The controller of this website is: 

UNIQA Insurance Group AG 
Untere Donaustraße 21 
1029 Vienna, Austria 

Registered in the Official Business Register under No. ATBRA.FN92933t 

Operating in the Slovak Republic through its branch: 

UNIQA Insurance Group AG, branch office 
Palárikova 2852/3 
949 01 Nitra 
Slovak Republic 

Company ID : 56 896 590 
Tax ID : 412011449 
VAT ID: SK412011449 

Registered in the Commercial Register of the District Court Nitra, Section Po, Insert No. 11056/N. 

3. Scope of Personal Data Processed 

When visiting the website, the following categories of personal data may be processed automatically: 

  • IP address and technical or security logs; 
  • Internet browser type and version, operating system, language settings, device type, and screen resolution; 
  • Date and time of the visit, pages visited, source of the visit, and referring website; 
  • Online and analytics identifiers and cookie preference information; 
  • Website usage data, such as visit duration, clicks, scroll depth, on-site searches, and repeat visits, provided that the data subject has consented to the use of analytical technologies; 
  • Approximate geographic location derived from technical connection data. 

The website does not contain any forms, and the analytics tools used do not collect information that directly identifies visitors. 

4. Purposes of Processing, Legal Bases and Retention Periods 

The use of cookies on the Controller's website is governed in particular by Article 6(1)(a) of the GDPR and Section 109 of Act No. 452/2021 Coll. on Electronic Communications. 

Technically Necessary Cookies 

Purpose: Technical operation, availability, security, and protection of the website 

The Controller processes personal data, including IP addresses, technical and security logs, and device-related information, to ensure the proper operation, availability, and security of the website. 

The processing is based on the Controller's legitimate interest pursuant to Article 6(1)(f) GDPR, consisting of ensuring the functionality of the website, protecting information systems, preventing security incidents, and responding to such incidents. 

Personal data are retained for the period necessary to ensure the operation and security of the website and to investigate and resolve potential security incidents, in accordance with the Controller's internal policies and the technical configuration of the hosting infrastructure. 

Marketing Cookies 

Purpose: Optimization of marketing activities and display of relevant content on the website 

Personal data, including online identifiers, cookie preference information, and data related to marketing activities and user preferences, may be processed for the purposes of personalizing marketing communications, measuring the effectiveness of marketing activities, and displaying relevant content and advertising. 

The processing is based on the data subject's consent pursuant to Article 6(1)(a) GDPR. 

Personal data are retained for the retention period applicable to each individual marketing cookie or similar technology. Detailed information regarding the provider, purpose, and retention period of individual marketing cookies is available in the Cookie Policy. 

Analytics Cookies 

Purpose: Analysis of website traffic and website usage through Adobe Analytics 

The Controller processes personal data relating to website visits, device information, online identifiers, and interactions with website content for the purpose of analyzing website traffic and usage through Adobe Analytics. 

The processing is based on the data subject's consent pursuant to Article 6(1)(a) GDPR. 

Personal data processed through Adobe Analytics are retained for a maximum period of 25 months from the date of the website visit. 

Visitors are free to refuse consent to the use of analytics and marketing technologies without any impact on their access to the core content and functionality of the website. 

The processing of certain technical data is, however, necessary to ensure the availability, security, and basic operation of the website. 

5. Adobe Analytics 

For the purpose of analyzing website traffic and usage, the Controller uses Adobe Analytics, a web analytics service provided and operated within the UNIQA Group. 

The processing of personal data through Adobe Analytics is based on the data subject's consent pursuant to Article 6(1)(a) of the GDPR. Consent may be granted, refused, or withdrawn at any time through the “Cookie Settings”. Analytics technologies are activated only after the relevant consent has been obtained. 

The data collected is used to evaluate website traffic, analyze the use of the website, and optimize its content, functionality, and user experience. 

Adobe Analytics enables the creation of aggregated website usage analyses and reports on website activity. Through Adobe Analytics, the following categories of data may be processed in particular: 

  • traffic sources; 
  • browser type and version; 
  • device model; 
  • operating system; 
  • language settings; 
  • screen resolution; 
  • approximate geographic location; 
  • pages visited; 
  • time spent on the website; 
  • clicks and interactions; 
  • scroll depth; 
  • on-site searches; and 
  • the number of repeat visits. 

Before any further processing takes place, the identifiability of IP addresses is technically restricted in accordance with the configuration settings of Adobe Analytics. 

Adobe Analytics is provided by Adobe Systems Software Ireland Limited. Data collected through Adobe Analytics is processed on Adobe servers located in London, United Kingdom. 

Personal data processed through analytics technologies is retained for a maximum period of 25 months from the date of the website visit. Individual tracking data may be retained for a shorter period, depending on the configuration of Adobe Analytics. 

The Adobe Analytics solution operates under the existing UNIQA Group account administered in Austria. To the extent necessary, personal data may be accessed by UNIQA Group companies providing centralized IT, analytics, or administrative services, exclusively on the basis of an appropriate legal and contractual framework governing the protection of personal data. 

In connection with the operation of the website, the Controller does not carry out automated individual decision-making, including profiling within the meaning of Article 22 GDPR, that would produce legal effects concerning the data subject or similarly significantly affect them. 

Detailed information regarding specific analytics cookies, including their names, providers, purposes, and retention periods, is available in the Cookie Policy. 

6. Amazon Web Services (AWS) Hosting 

The website is operated using external cloud and hosting infrastructure provided by Amazon Web Services (AWS). 

In connection with the provision of hosting services, the following categories of data may be processed to the extent necessary to ensure the operation, availability, and security of the website: 

  • IP addresses; 
  • technical device information; and 
  • server and security logs. 

Personal data processed in connection with hosting services is retained only for the period necessary to ensure the proper operation, availability, and security of the website and to investigate and resolve potential security incidents. 

7. Cookie Consent Management 

The website uses a cookie consent management solution developed and operated within the UNIQA Group. 

Through this solution, visitors can provide or refuse consent to the use of optional cookies and similar technologies and may subsequently modify their preferences at any time through the "Cookie Settings" option available on the website. 

Strictly necessary cookies are used without consent only to the extent required to ensure the basic functionality of the website. Analytics and marketing cookies are activated only after the relevant consent has been granted. 

Detailed information about the cookies used, including their categories, purposes, providers, and retention periods, is available in the separate Cookie Policy. 

8. Careers Section and External Job Portals 

The website is not intended for the submission of CVs, job applications, or other recruitment-related documents. The careers section contains only links to external job portals or recruitment systems operated in the respective countries: 

  • Slovakia: profesia.sk 
  • Bulgaria: jobs.bg 
  • Romania: mingle.ro 
  • Hungary: profession.hu 

Once a visitor is redirected to an external job portal or recruitment system, any subsequent processing of personal data is governed exclusively by the privacy policy and terms and conditions of the relevant portal or recruitment system operator. 

9. External Links, Social Media and YouTube 

The website may contain links to third-party websites and to the Controller’s social media profiles. These are standard hyperlinks only; third-party content is not directly embedded into the website. 

When a visitor follows a link to a third-party website or platform, any subsequent processing of personal data is carried out in accordance with the privacy policies and practices of the respective third-party operator. 

Visitors are encouraged to review the privacy policies of the relevant third-party operators before providing any personal data. 

The Controller is not responsible for the privacy practices or content of third-party websites to which the website may link. 

The website does, however, contain embedded YouTube videos. When such videos are loaded or played, cookies and certain technical information may be processed by YouTube. The Controller is currently working on a technical solution that will allow external multimedia content to be loaded only after the user has provided the relevant consent. 

10. Recipients of Personal Data 

Personal data may be disclosed, to the extent necessary, to the following categories of recipients: 

  • Amazon Web Services (AWS), as the provider of the cloud and hosting infrastructure used to ensure the operation, availability, and security of the website; 
  • providers of website development, maintenance, and technical support services; 
  • UNIQA Group companies providing centralized IT, analytics, and related support services; 
  • Adobe Systems Software Ireland Limited and any subcontractors involved in the provision of Adobe Analytics services; 
  • public authorities and governmental bodies where disclosure is required by applicable law. 

11. Transfers of Personal Data Outside the European Economic Area 

In connection with the use of Adobe Analytics, personal data is processed on Adobe servers located in London, United Kingdom. Transfers of personal data to the United Kingdom are based on the adequacy decision adopted by the European Commission pursuant to Article 45 GDPR. 

Where personal data is transferred to another country outside the European Economic Area in connection with hosting services, analytics services, or the engagement of additional service providers, the Controller shall ensure that such transfer is based on an appropriate legal transfer mechanism and adequate safeguards in accordance with Chapter V GDPR, in particular an adequacy decision adopted by the European Commission or the Standard Contractual Clauses approved by the European Commission. 

12. Personal Data Security 

The Controller implements appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, alteration, loss, unauthorized disclosure, or unauthorized access. 

Such security measures are implemented taking into account the nature, scope, context, and purposes of the processing, as well as the risks to the rights and freedoms of data subjects. 

Despite the measures implemented, due to the inherent risks associated with the internet, the absolute security and confidentiality of data transmitted online cannot be guaranteed. 

13. Data Subject Rights 

Subject to the conditions set out in Articles 12 to 22 of the General Data Protection Regulation (GDPR), data subjects have, in particular, the right to: 

  • obtain confirmation as to whether personal data concerning them is being processed and, where that is the case, access to such personal data; 
  • request the rectification of inaccurate personal data and the completion of incomplete personal data; 
  • request the erasure of personal data where the applicable legal requirements are met; 
  • request the restriction of processing where the applicable legal requirements are met; 
  • receive personal data in a structured, commonly used, and machine-readable format and exercise the right to data portability where the applicable legal requirements are met; 
  • object to processing based on the Controller's legitimate interests; 
  • withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. 

Data subjects may exercise their rights by contacting the Controller at: 

GDPR-UGS@uniqa.at 

14. Supervisory Authority 

Pursuant to Article 77 GDPR, data subjects have the right to lodge a complaint with a supervisory authority if they consider that the processing of personal data relating to them infringes the GDPR or applicable data protection laws. 

The competent supervisory authority is: 

Office for Personal Data Protection of the Slovak Republic 
Galvaniho Business Centrum II 
Galvaniho 7/B 
821 04 Bratislava 
Slovak Republic 

Company ID: 36 064 220 
E-mail: statny.dozor@pdp.gov.sk 
Telephone: +421 2 32 31 32 14, +421 2 32 31 32 49 

Website: https://dataprotection.gov.sk/en/ 

This right is without prejudice to the data subject's right to lodge a complaint with a supervisory authority in the Member State of their habitual residence, place of work, or the place of the alleged infringement, and without prejudice to any other administrative or judicial remedy available under applicable law. 

15. Changes to this Privacy Policy 

The Controller reserves the right to update this Privacy Policy periodically, in particular where changes occur in the purposes or means of processing, technologies used, service providers, or applicable legal requirements. 

The current version of this Privacy Policy will always be published on the website together with its effective date. 

16. Processing of Children's Personal Data 

The website is not intended for children, and the Controller does not knowingly collect personal data relating to children through the website. 

If the Controller becomes aware that personal data relating to a child has been collected through the website without proper authorization, appropriate measures will be taken to delete such data or otherwise address the matter in accordance with applicable legal requirements. 

17. Contacting the Controller 

For any questions relating to the protection of personal data or for exercising data subject rights, please contact: 

GDPR-UGS@uniqa.at 

If a data subject has questions regarding the processing of personal data or wishes to exercise their rights, they may contact the Controller using the contact details provided in this Privacy Policy. 

The Controller will provide reasonable assistance in handling requests and inquiries relating to the protection of personal data.