Last updated: October 5, 2026 · Effective from: November 1, 2026 (version 1.1)
1. Data Controller
The controller of personal data is:
TTN, s.r.o. Sadová 2719/3A, 905 01 Senica, Slovak Republic Company ID (IČO): 52330443 | Tax ID (DIČ): 2120984085 | VAT ID: SK2120984085 Registered in the Commercial Register of the District Court of Trnava, Section Sro, Insert No. 44230/T E-mail: privacy@ttn.sk
(hereinafter "Controller" or "we")
This Privacy Policy (hereinafter "Policy") explains how we collect, process, store and protect personal data of users of the Portali.Space customer portal, which we operate as the HelpDesk and MaintenanceDesk products (hereinafter "Portal").
The Portal is operated under the brands Portali.Space, HelpDesk, MaintenanceDesk, WorkSys.Space, FacilityUp.Space, CitySys.Space and TTN. Regardless of the brand used, the Controller is always TTN, s.r.o.
1.1. Our Roles in Processing
TTN acts in two roles:
- as controller for data whose purposes and means of processing we determine ourselves: user accounts and sign-in, communication with you, invoicing and management of the contractual relationship, Portal security, traffic measurement (only with consent) and handling inquiries from the website. This Policy applies to such processing.
- as processor for content that your organization enters into the Portal (tickets and their attachments, devices, contacts, knowledge base, AI Assistant data created within the organization). The controller of such data is your organization; TTN processes them on its instructions under the Data Processing Agreement (DPA), which is an annex to the Terms of Service. Please direct questions about such data to your organization’s administrator.
2. Personal Data We Collect
2.1. Data Provided by the User
| Category | Examples | Purpose |
|---|---|---|
| Identification data | Name, surname, e-mail address | Registration, authentication, communication |
| Organizational data | Organization name, job title | Organization assignment, SLA management |
| Ticket content | Subject, problem description, comments, attachments | Providing customer support |
| Communication data | E-mail correspondence, notifications | Informing about ticket status |
2.2. Data Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Technical data | IP address, browser type, operating system | Security, diagnostics |
| Usage data | Pages visited, device type, time of visit | Measuring traffic — only with consent (Section 5.2) |
| Cookies | Sessions, language preferences | Portal functionality |
2.3. Data from the AI Assistant (if activated)
| Category | Examples | Purpose |
|---|---|---|
| User questions | Text of questions entered into the AI chat | Generating responses |
| AI context | Portal content needed for the answer that you are allowed to see: knowledge base articles, tickets and comments including the names of people mentioned in them (e-mail addresses and phone numbers are replaced with placeholder text before sending), data on devices, maintenance and spare parts; your role and the brand name | Contextual responses |
| AI responses | Text of generated responses | Display to the User |
| AI metadata | Token count, response time, model used | Monitoring, billing |
2.4. Add-on Inquiry from the Website
If you fill in the “I am interested in the add-on” form (Quality audits add-on) on our pricing page, we process your name, company name, e-mail address and, optionally, phone number, number of gauges and message, as well as the page language and address, the time of submission and the version of this Policy you were informed of. We do not store your IP address in readable form, only as a one-way cryptographic fingerprint (hash).
- Purpose: handling your inquiry, preparing an offer and contacting you about the add-on.
- Legal basis: the Controller’s legitimate interest in handling a business inquiry and communicating with a representative of a prospective customer — Art. 6(1)(f) GDPR. If you submit the inquiry as a sole trader in your own name, the processing constitutes steps taken at your request prior to entering into a contract — Art. 6(1)(b) GDPR. The IP fingerprint and the Cloudflare Turnstile check — legitimate interest in protecting the form against abuse (Art. 6(1)(f) GDPR). By ticking the box in the form you confirm that you have read this information; this is not consent under Art. 6(1)(a) GDPR. You may object to processing based on legitimate interest (Section 8.6).
- Provision of data: your name, company name and e-mail address are required to handle the inquiry; without them we cannot handle it. All other data are optional.
- Retention: the IP fingerprint is deleted 12 months after the inquiry is received. A handled (closed) inquiry is anonymized 24 months after receipt; any other inquiry no later than 36 months after receipt. After anonymization only the company name, number of gauges, status and dates remain (for statistical purposes). Backups may retain the data for up to 6 further months.
- Recipients: authorized staff of the Controller; processors — Mailgun (Sinch) for e-mail delivery, the hosting infrastructure provider and Cloudflare, Inc. (Turnstile verification, network infrastructure) — see Section 4.
3. Purposes and Legal Bases for Processing
3.1. Overview of Purposes
| Purpose | Legal Basis (GDPR) | Retention |
|---|---|---|
| Providing Services (helpdesk, KB, reporting) | Performance of contract — Art. 6(1)(b) | Duration of account + 4 years after account deletion (limitation period under Section 397 of the Slovak Commercial Code) |
| Account management and authentication | Performance of contract — Art. 6(1)(b) | Duration of account + 4 years after account deletion (limitation period under Section 397 of the Slovak Commercial Code) |
| Invoicing and management of the contractual relationship (paid plans) | Performance of contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) | Accounting documents 10 years (Slovak Act No. 431/2002 Coll. on Accounting) |
| E-mail notifications about tickets | Performance of contract — Art. 6(1)(b) | Duration of account |
| AI Assistant — generating responses | Consent — Art. 6(1)(a) | Locally: duration of account. At the AI provider: by default up to 30 days |
| Security and abuse prevention | Legitimate interest — Art. 6(1)(f) | 12 months |
| Legal compliance | Legal obligation — Art. 6(1)(c) | As required by applicable law |
| Measuring traffic and usage of the Portal (Google Analytics 4) | Consent — Art. 6(1)(a) | 14 months |
| Handling add-on inquiries from the website (Section 2.4) | Legitimate interest — Art. 6(1)(f); for a sole trader Art. 6(1)(b) | Closed inquiry 24 months, any other at the latest 36 months after receipt (then anonymized); IP fingerprint 12 months |
3.2. Legitimate Interests
Where the legal basis is legitimate interest (Art. 6(1)(f)), this relates to:
- ensuring the security and integrity of the Portal,
- fraud and abuse prevention,
- protecting web forms (sign-in, registration, add-on inquiry) against automated abuse,
- handling business inquiries and communicating with representatives of prospective customers.
These interests have been assessed through a balancing test and do not override the rights and freedoms of data subjects. You have the right to object to processing on this basis (Section 8.6).
4. Recipients of Personal Data
4.1. Categories of Recipients
| Recipient | Purpose | Location | Safeguards |
|---|---|---|---|
| Anthropic Ireland, Limited (Ireland) — provider of the Claude model | AI Assistant — processing of questions and of the Portal content needed for the answer (Section 6); machine translation of knowledge base articles | USA; for some requests also other countries in which the provider operates computing infrastructure | Data processing agreement (DPA) with Standard Contractual Clauses (SCC); the provider has contractually undertaken not to use our data to train models |
| Mailgun (Sinch) | Delivering e-mail notifications | EU | DPA + SCC |
| Hosting infrastructure provider | Portal infrastructure hosting — infrastructure layer only, without logical access to data; the servers are managed by TTN, disks are encrypted | EU | DPA, ISO 27001 |
| Organization administrators | Managing users within their organization | — | Contractual terms |
| Google Ireland Limited (Google Analytics 4) | Measuring traffic and usage of the Portal — only with consent | EU/USA | DPA + EU-US Data Privacy Framework; subsidiarily Standard Contractual Clauses (SCC) included in the DPA |
| Cloudflare, Inc. | Cloudflare Turnstile verification at sign-in, registration and when submitting an add-on inquiry; network infrastructure (proxy) in front of the services on the portali.space domain — mainly processes the IP address and technical browser data | EU/USA | DPA + EU-US Data Privacy Framework; subsidiarily Standard Contractual Clauses (SCC) included in the DPA |
4.2. Transfers to Third Countries
For the AI Assistant and the machine translation of knowledge base articles, we pass data to the AI provider (Anthropic Ireland, Limited, Ireland). It may process the data outside the EU/EEA — in the USA and, for some requests, also in other countries in which it operates computing infrastructure. These transfers are safeguarded by:
- Standard Contractual Clauses (SCC) under European Commission Decision 2021/914, which form part of the data processing agreement (DPA) with the provider,
- supplementary measures (encryption in transit; for the AI Assistant, limitation of the scope of data under Section 6.2).
For Google Analytics 4 (only with consent), data may be transferred to Google LLC in the USA. Such transfers rely on the European Commission's adequacy decision of 10 July 2023 for the EU-US Data Privacy Framework, under which Google LLC is certified.
For Cloudflare services, data (mainly the IP address) may be processed by Cloudflare, Inc. in the USA. Such transfers rely on the same adequacy decision (EU-US Data Privacy Framework), under which Cloudflare, Inc. is certified, and on the data processing terms (DPA).
The data processing terms (DPA) of Google and Cloudflare also contain the Standard Contractual Clauses (SCC) pursuant to Decision 2021/914, which apply as a transfer safeguard should the adequacy decision (EU-US Data Privacy Framework) cease to be valid.
5. Cookies and Similar Technologies
5.1. Strictly Necessary Cookies
The Portal uses strictly necessary (functional) cookies to ensure basic functionality:
| Cookie | Purpose | Duration |
|---|---|---|
wlp-portal-session |
User login and session | 2 hours from last activity |
XSRF-TOKEN |
Protection of forms against forged requests (CSRF) | 2 hours |
remember_web_… |
Persistent login — only if you select “Remember me” when signing in | 400 days |
timezone |
Browser time zone for correct display of times | 1 year |
cookie_consent |
Storing your choice in the cookie banner | 1 year |
These cookies are strictly necessary for the operation of the Portal or for providing a feature you have explicitly requested, and do not require consent under Art. 5(3) of Directive 2002/58/EC (ePrivacy) and Section 109(8) of Slovak Act No. 452/2021 Coll. on Electronic Communications.
Some settings (e.g. dark mode or dismissed notices) are stored by the Portal only in your browser’s local storage; they are not sent to the server and you can delete them in your browser settings. Neither Cloudflare Turnstile verification nor the Cloudflare network stores cookies on your device.
5.2. Analytics Cookies (Google Analytics 4)
If you give your consent in the cookie banner (category “Analytics”), the Portal uses Google Analytics 4 to measure traffic and usage of the Portal (e.g. which pages are viewed, how often and from what type of device). Without consent, Google Analytics is not loaded and no data are sent to Google servers.
- Data processed: a pseudonymous browser identifier (cookie
_ga), pages visited and their titles, time of visit, language, type of device, browser and operating system, country and region derived from the IP address (Google Analytics 4 does not store IP addresses; granular location and device data collection is switched off for the EU); within the Portal also the portal brand, whether the User is signed in, and the User's role. Names, e-mail addresses and ticket contents are not sent to Google Analytics. - Purpose: measuring traffic and usage of the Portal and improving its content and features.
- Legal basis: consent — Art. 6(1)(a) GDPR (in conjunction with Art. 5(3) of Directive 2002/58/EC and Section 109(8) of Slovak Act No. 452/2021 Coll.).
- Withdrawal of consent: you can withdraw your consent at any time with effect for the future via the “Cookie settings” link in the page footer (switch off the “Analytics” category). After withdrawal, Google Analytics is not loaded and no further data are sent. The Portal also deletes the
_gaand_ga_<ID>cookies from your browser. Withdrawal does not affect the lawfulness of processing before withdrawal. - Retention: user-level and event-level data are kept in Google Analytics for 14 months and then deleted automatically; aggregated statistics without personal data may be kept.
- Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as processor. Data may also be transferred to Google LLC in the USA on the basis of the EU-US Data Privacy Framework (see Section 4.2).
| Cookie | Purpose | Duration |
|---|---|---|
_ga |
Distinguishing visitors (pseudonymous identifier) | 2 years (renewed on each visit) |
_ga_<ID> |
Maintaining session state | 2 years (renewed on each visit) |
<ID> is the measurement ID of the respective portal without the “G-” prefix (e.g. _ga_X6918V882V).
6. AI Assistant — Data Processing
6.1. Description of Processing
The AI Assistant is an optional feature. You use it only if your organisation has it enabled and you yourself have agreed to it; you can withdraw your consent at any time. Answers are generated by the Claude model of Anthropic (the contracting entity is stated in Section 4.1), which processes data for us as a processor under a data processing agreement.
Whenever you use the AI Assistant, the interface clearly states that you are communicating with an automated artificial intelligence system, not a human (Article 50 of Regulation (EU) 2024/1689 on artificial intelligence).
What always applies:
- The AI Assistant sees only what you are allowed to see in the Portal — according to your role and brand. A customer, for example, sees only their own tickets, without internal notes.
- Your data is not used to train artificial intelligence models, and we do not sell it.
- Nothing is sent to the AI provider in advance or in the background — only when you ask a question, and only what the AI Assistant requests in order to answer it.
- You can delete your conversation history at any time.
How it works:
- Your question is received by the Portal server.
- The server sends it to the AI provider together with the previous messages of the conversation, your role and the brand name.
- Where needed for the answer, the AI Assistant requests further content from the Portal — a knowledge base article, a ticket with its comments, or data on a device, maintenance plan or spare part.
- The AI provider returns the answer and the Portal displays it to you.
- At your express request, the AI Assistant can carry out an action on your behalf (e.g. create a ticket or add a comment) — always only within your permissions. An action carried out by the AI Assistant at your request is considered your own action.
6.2. What Is Sent and What Is Not
The AI provider receives the text of your question as you write it, and the Portal content that the AI Assistant requests for the answer.
Before sending, we automatically replace e-mail addresses and phone numbers in this content with placeholder text. Names of people mentioned in tickets and comments remain, because without them the AI Assistant could not give a meaningful answer (e.g. who is handling a ticket). Automatic replacement may not catch every unusual notation, which is why we do not describe the data as anonymised.
We limit the scope as follows:
- only content you have access to in the Portal; data of other organisations is not sent,
- long texts are shortened (ticket description, comments, articles),
- ticket attachments are not sent,
- the Portal does not add passwords, IP addresses or payment data to your question,
- cost data is provided to the AI Assistant only when an organisation administrator asks,
- we do not add your name, e-mail address or other account data to your question — only your role, the brand name, the interface language and the date.
Whatever you write in your question, or whatever is written in the text of a ticket, is sent in that wording. Please do not enter passwords or sensitive personal data (e.g. national identification numbers or health data) in your questions.
6.3. AI Provider Safeguards
| Property | Detail |
|---|---|
| Training on data | The provider has contractually undertaken not to use content from our service to train its models |
| Data retention | By default, the provider deletes inputs and outputs within 30 days. It may keep them longer only in the cases set out in its terms — in particular when investigating a breach of its usage policies or where required by law |
| Contractual basis | Data processing agreement (DPA) with Standard Contractual Clauses (SCC) |
| Role | Processor; for your organisation's content, sub-processor (Art. 28 GDPR) |
| Place of processing | USA; for some requests also other countries in which the provider operates computing infrastructure |
More information: https://privacy.claude.com
6.4. Legal Basis
Processing of data through the AI Assistant is based on the User's consent (Art. 6(1)(a) GDPR). Consent is requested before first use of the AI Assistant and may be withdrawn at any time.
6.5. Consequences of Consent Withdrawal
Withdrawal of consent: - disables the AI Assistant for the given User, - does not affect the lawfulness of processing prior to withdrawal, - does not affect other Portal Services.
6.6. Local Storage of AI Conversations
Your questions and the AI Assistant's answers are stored in the Portal database so that you can continue a conversation and return to it. Content that the AI Assistant requested from the Portal while answering is not stored in the history. Separately, we record usage (model, number of tokens, cost) for billing purposes — without the text of the conversation.
You can delete your history at any time directly in the AI Assistant window. It is also deleted when you withdraw your consent, unless you untick that option. Usage records are not deleted. AI conversations created within an organisation are processed by TTN as a processor (Section 1.1(b)).
7. Data Retention Periods
| Data Category | Retention Period |
|---|---|
| Account data (name, e-mail) | Duration of account + 4 years after account deletion |
| Ticket content | Duration of account + 4 years after account deletion |
| E-mail notifications | 12 months |
| AI conversations (local) | Duration of account (User may delete at any time) |
| AI data at the AI provider | By default up to 30 days (Section 6.3) |
| Security logs | 12 months |
| Invoices and accounting documents | 10 years (legal obligation) |
| Google Analytics 4 data (only with consent) | 14 months |
| Add-on inquiries from the website | Closed inquiry 24 months, any other at the latest 36 months after receipt (then anonymized); IP fingerprint 12 months |
| Suspended free account (Section 4.5 of the Terms) | Deleted 12 months after suspension unless reactivated; prior notice by e-mail |
For data for which TTN is a processor (Section 1.1(b)), the retention period is determined by your organization; after the contract ends we proceed in accordance with the DPA.
After the retention period expires, data are securely deleted or anonymized.
8. Data Subject Rights
Under Regulation (EU) 2016/679 (GDPR), you have the following rights:
8.1. Right of Access (Art. 15)
You have the right to obtain confirmation as to whether your personal data are being processed, and if so, to access them and information about the processing.
8.2. Right to Rectification (Art. 16)
You have the right to have inaccurate personal data corrected and incomplete data supplemented.
8.3. Right to Erasure (Art. 17)
You have the right to request erasure of your personal data if: - the data are no longer necessary for the purposes for which they were collected, - you withdraw consent (e.g. for the AI Assistant) and there is no other legal basis, - you object to processing and there are no overriding legitimate grounds.
For AI history: Users can delete AI conversations directly in the Portal settings.
8.4. Right to Restriction of Processing (Art. 18)
You have the right to request restriction of processing in cases specified by the GDPR.
8.5. Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, commonly used and machine-readable format (JSON) and to transmit them to another controller.
8.6. Right to Object (Art. 21)
You have the right to object to processing based on legitimate interest. In such case, we will cease processing unless we demonstrate compelling legitimate grounds.
8.7. Right to Withdraw Consent (Art. 7(3))
Where processing is based on consent (e.g. AI Assistant or analytics cookies), you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
8.8. Right to Lodge a Complaint
You have the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection of the Slovak Republic Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovakia Web: https://dataprotection.gov.sk E-mail: statny.dozor@pdp.gov.sk Phone: +421 2 32 31 32 14, +421 2 32 31 32 49
8.9. Exercising Your Rights
You may exercise your rights: - By e-mail to: privacy@ttn.sk - In writing to the Controller's registered office
We will respond to your request within one month of receipt. In justified cases, this period may be extended by a further 2 months, of which we will inform you.
8.10. Requests Concerning Your Organization’s Data
If your request concerns data for which TTN is a processor (ticket content and your organization’s data), we will forward it to your organization’s administrator as the controller and inform you accordingly.
9. Data Security
9.1. The Controller implements appropriate technical and organizational measures to protect personal data, including:
| Measure | Detail |
|---|---|
| Encryption in transit | TLS 1.2+ (HTTPS) on all endpoints |
| Encryption at rest | Database and backup encryption |
| Access control | Role-based access control (RBAC) — Users see only data they are authorized to access |
| Brand isolation | Data are strictly separated between brands — a customer of one brand never sees data of another |
| Data minimization | We pass to external services only the data needed for the given purpose. The AI Assistant receives only content that the User who asked the question is allowed to see; attachments are not sent (Section 6.2); e-mail addresses and phone numbers are replaced with placeholder text before sending, and the User's name is not added to the question. |
| Audit log | Records of access and changes; for the AI Assistant, a record of consent being given and withdrawn and of usage, without the text of the conversation. |
| Backup | Regular encrypted backups |
| ISO 27001 | The Controller is ISO 27001 certified |
| Incident response | Defined procedure for security incidents including notification to the supervisory authority within 72 hours pursuant to Art. 33 GDPR |
10. Changes to This Policy
10.1. The Controller reserves the right to update this Policy, particularly due to legislative changes, addition of new Services or changes in data processing.
10.2. Users will be informed of material changes through: - a notice on the Portal, - an e-mail notification.
10.3. The version and the effective date are always indicated at the beginning of this document. Previous versions are available in the archive on the Portal.
11. Contact Information
For questions regarding personal data protection, please contact us:
TTN, s.r.o. Sadová 2719/3A, 905 01 Senica, Slovak Republic Registered in the Commercial Register of the District Court of Trnava, Section Sro, Insert No. 44230/T E-mail: privacy@ttn.sk Web: https://ttn.sk