Privacy

Privacy Policy

This policy explains how personal data is processed when you use the Mondieu website, contact us or choose optional website services.

Last updated: 29 July 2026

1. Data controller

The controller responsible for the processing described in this policy is:

Company
MON-DIEU, s. r. o.
Registered address
Záhradnícka 29, 811 07 Bratislava – Staré Mesto, Slovakia
Company ID
47 097 418
Privacy contact
osobneudaje@mondieu.sk

2. Personal data we process

Depending on how you use the website, we may process the following categories of data:

  • Technical and access data: IP address, date and time of access, requested URL, referrer, browser and device information, and security or diagnostic logs generated by our hosting infrastructure.
  • Communication data: your name, email address and any information you voluntarily include when contacting us, applying for a role or submitting the franchise inquiry form.
  • Location data: only after you actively request the nearest-location feature. Your coordinates are used in your browser to calculate distances and are not sent to Mondieu by this website.
  • Consent data: your selected consent categories, policy version and selection time. This record is stored locally in your browser.
  • External-media data: after you consent to external media, providers such as Google Maps may receive your IP address, device information and interaction data and may use their own cookies or similar technologies.

3. Purposes and legal bases

Website delivery and security

We process technical data to deliver, maintain and protect the website based on our legitimate interests under Article 6(1)(f) GDPR.

Communication and requests

We process information you send us to respond, take steps at your request or manage a relationship with you under Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the request.

Legal obligations and claims

We may process data where required by law under Article 6(1)(c) GDPR and where necessary to establish, exercise or defend legal claims under Article 6(1)(f) GDPR.

Optional analytics, marketing and external media

Optional technologies are activated only after your consent under Article 6(1)(a) GDPR and applicable electronic communications rules. You may refuse or withdraw consent without losing access to the basic website.

4. Cookies and local storage

Optional categories are disabled by default. You can accept all, reject all optional categories or make a granular choice. Your choice is remembered for 180 days in local storage under the key “mondieu-cookie-consent”.

Strictly necessary

Always active

Required for website security, core operation, form abuse prevention through Cloudflare Turnstile and remembering your consent choice. These technologies cannot be disabled through the consent tool.

Analytics

Optional

Intended to measure website use and improve performance. No analytics provider is currently active; future analytics scripts marked for this category will remain blocked until you consent.

Marketing

Optional

Intended for advertising measurement or personalised marketing. No marketing provider is currently active; future marketing scripts marked for this category will remain blocked until you consent.

External media

Optional

Allows third-party content such as Google Maps. Until you consent, the external content is not loaded and no connection is initiated by the embedded element.

5. Recipients and service providers

Personal data may be processed by Cloudflare for hosting, security and Turnstile verification, by Amazon Web Services for delivery of franchise inquiries through Amazon SES, by our professional advisers and email providers when you contact us, and by public authorities where legally required. Google receives data through embedded Maps only after external-media consent. Providers may act as processors or independent controllers according to their service and terms.

6. International transfers

Some providers may process data outside the European Economic Area. Where GDPR applies, transfers must rely on an applicable adequacy decision, Standard Contractual Clauses or another safeguard permitted by Chapter V GDPR. Details of a provider’s safeguards are available in its privacy documentation.

7. Retention

  • Technical and security logs are retained only for the period needed to operate, secure and diagnose the website, according to the hosting configuration and applicable legal requirements.
  • Correspondence is retained for as long as needed to handle the request and afterwards only for applicable statutory limitation, accounting or legal-obligation periods.
  • The consent record remains in your browser for up to 180 days, unless you clear browser storage or change your choice sooner.
  • Data processed solely on consent is no longer used for that purpose after withdrawal, without affecting processing performed before withdrawal.

8. Your rights

Subject to the conditions in the GDPR, you may request:

  • access to your personal data and a copy of it;
  • correction of inaccurate or incomplete data;
  • erasure of your data;
  • restriction of processing;
  • data portability;
  • an objection to processing based on legitimate interests;
  • withdrawal of consent at any time.

You also have the right to lodge a complaint with the competent supervisory authority. The controller’s lead contact is listed below.

9. Withdrawing or changing consent

Use the “Cookie settings” link in the footer at any time. Refusing or withdrawing optional consent does not affect basic website access. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

10. Automated decision-making

This website does not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

11. Security

We use proportionate technical and organisational measures intended to protect personal data. No internet transmission or storage system can be guaranteed to be completely secure.

12. Children

This website is not intended to knowingly collect personal data directly from children. A parent or guardian who believes a child has provided data should contact us.

13. Changes to this policy

We may update this policy when the website, providers or legal requirements change. The current version and update date are published on this page. We will request consent again where a change requires renewed consent.

14. Contact and complaints

Send privacy requests to the controller’s privacy email. You may also contact the supervisory authority:

osobneudaje@mondieu.sk

Supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky

Existing detailed policy document

The existing brand policy document remains available for processing related to services described in that document. If this website policy and that document address different processing activities, the notice specific to the relevant activity applies.

Open existing policy document