📌 TL;DR — in short
- We process only the data that is necessary for the service to work.
- We do not sell your data. Not to any data broker.
- We host in the European Union (Hostcreators, Slovakia).
- Your data is yours. You can export or delete it at any time.
- We split cookies into 3 categories: essential (always on), analytics and marketing (only with your consent).
- You can .
1. Controller
The controller of personal data is WEIDO, s.r.o., Konventná 6, 811 03 Bratislava – Staré Mesto, Slovak Republic, Company ID (IČO): 50 860 640.
Contact for data protection matters: ,
2. What data we process
On registration and while you use the account:
- your name (or a nickname),
- your e-mail address,
- your password (stored as a secure hash — not visible even to us),
- your chosen language and interface theme,
- your IP address and browser User-Agent (security logs, 30 days at most).
- First-party traffic statistics (server-side analytics): we store every pageview in our own database together with the following — IP address, User-Agent, device type (mobile/desktop), browser, operating system, country and city (derived from the IP via ip-api.com), page URL, referring page and language. This data stays exclusively on our server (saldat.com), is not sent to any third party (Google, Meta, Microsoft), uses no cookies and is not conditional on consent. The visitor identifier is a hash that is rotated automatically every day — we do not identify you across days unless you have an account. Purpose: operational statistics, content optimisation and security. Legal basis: GDPR Art. 6(1)(f) (legitimate interest). Retention: 12 months, then automatic purge.
Financial data you enter yourself:
- transactions, categories, accounts, goals, budgets, investments and loans,
- uploaded receipts (optional),
- settings (currency, alert thresholds, linked accounts).
When you pay: Stripe acts as the payment processor (we neither see nor store card numbers — we only see the transaction ID and the last 4 digits).
We have no bank integration yet. You import data manually or via CSV.
3. Purpose and legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service (dashboard, reports…) | Performance of a contract (Art. 6(1)(b)) |
| Securing the account, preventing misuse | Legitimate interest (Art. 6(1)(f)) |
| Payments and invoicing | Contract and legal obligation (Art. 6(1)(b)/(c)) |
| Transactional e-mails (verification, password reset) | Performance of a contract (Art. 6(1)(b)) |
| Marketing newsletters (optional) | Consent (Art. 6(1)(a)) — unsubscribe in one click |
4. Retention periods
- Account and financial data — for as long as your account is active. After you close it, we permanently delete it within 30 days.
- Technical backups — rotated automatically within 90 days.
- Security logs (IP, User-Agent) — 30 days.
- Invoices and tax documents — 10 years (Slovak Accounting Act).
5. Third parties (processors)
We use some services from external suppliers — all of them process data within the EU or with adequate safeguards:
- Hostcreators (SK) — hosting provider. Server located in the Slovak Republic.
- Stripe (Ireland, EU) — payment processor. Privacy Policy
- Resend (EU for EU accounts) — sender of transactional e-mails (planned, not active yet).
- European Central Bank — a feed of public FX rates (no personal data is shared).
- Google Tag Manager (Google Ireland Ltd., EU) — tag manager. GTM itself stores no personal data; it only loads other tags (GA, Pixel) according to your consent. Privacy Policy
We do not share your personal data with any other party. Analytics and marketing tags (Google Analytics, Meta Pixel, Google Ads) are loaded solely with your consent.
7. Your rights (GDPR)
As a data subject you have the right to:
- access your data (Art. 15) — you see all of it directly in your account, plus an export,
- rectification of inaccurate data (Art. 16) — edit it directly in the settings,
- erasure (the “right to be forgotten”, Art. 17) — close your account in the settings,
- restriction of processing (Art. 18),
- data portability (Art. 20) — export all of your data from your Account page,
- object to processing (Art. 21),
- withdraw consent at any time (where processing is based on consent).
Send your request to . We will reply within 30 days.
8. Complaints
If you believe we process your personal data unlawfully, you have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic:
Hraničná 12, 820 07 Bratislava 27 · dataprotection.gov.sk
9. Security
We protect your data with:
- HTTPS / TLS encryption across the whole site,
- password hashing via
password_hash()(Argon2id / bcrypt), - CSRF tokens in forms,
- optional two-factor authentication (TOTP),
- rate limiting on sign-in and registration,
- regular database backups.
No system is 100% secure, however. If we suspect a data breach we will inform you within 72 hours (GDPR Art. 33).
10. Minors
The service is not intended for anyone under 16 years of age. If we find that we have inadvertently processed a child’s data, we will delete it immediately.
11. Changes to this policy
We may update this policy. For material changes we will inform you by e-mail or by a notification in the application at least 14 days in advance.