Privacy Policy

Last updated: August 20, 2026.

This is an English translation for convenience. In case of any discrepancy, the Slovak version is the legally binding original governed by Slovak law.

1. Data Controller

The controller of your personal data is Elektrorepas, s. r. o., Turčiansky Peter 84, 038 41 Turčiansky Peter, Slovenská republika, Company ID (IČO): 57 115 893, registered in the Commercial Register of Okresný súd Žilina, Section Sro, Insert No. 88361/L (the "Controller" or "we"). Privacy contact: support@bluefromsky.com.

2. What personal data we process

3. Purposes and legal bases

Purpose Legal basis
Order processing, Certificate delivery, invoicingperformance of a contract (Art. 6(1)(b) GDPR)
Managing the customer accountperformance of a contract / consent
Handling complaints and contact-form requestsperformance of a contract / legitimate interest
Accounting and tax documentscompliance with a legal obligation (Art. 6(1)(c) GDPR, Slovak Accounting Act, VAT Act)
Transactional e-mails (order confirmation, OTP code, password reset)performance of a contract / legitimate interest
Traffic and behavior measurement (Google Analytics, Microsoft Clarity), advertising/remarketing (Facebook Pixel/App)consent (Art. 6(1)(a) GDPR) — activated only after consent is given via our cookie banner
Sign-in via Google/Facebookconsent / performance of a contract
Abuse prevention (reCAPTCHA, fraud prevention)legitimate interest (Art. 6(1)(f) GDPR)
Creating an independently verifiable blockchain record for the Certificatelegitimate interest (Art. 6(1)(f) GDPR)

4. Recipients and processors of personal data

Your personal data may be disclosed to the following recipients/processors, strictly to the extent necessary for the relevant purpose:

We have data processing agreements in place with the above processors under Art. 28 GDPR, or their processing is governed by their own privacy policies as independent controllers (in particular for third-party sign-in and cookies).

5. International data transfers

Some of the recipients above (in particular Google, Microsoft, Meta, and Stripe group companies) may process data outside the European Economic Area (e.g., in the US). In such cases, the transfer is safeguarded by appropriate measures — in particular Standard Contractual Clauses approved by the European Commission and/or the relevant company's participation in the EU–US Data Privacy Framework.

6. Cookies

Our website uses:

7. Retention periods

8. Your rights

Under the GDPR, you have the right to:

Note: the right to erasure is not absolute — personal data appearing on tax documents (invoices) must be retained even after account deletion for the period required by applicable law (Section 7), as this constitutes compliance with a legal obligation under Art. 17(3)(b) GDPR.

9. Account deletion

A request to delete an account can only be made by a signed-in Buyer through their customer account, after re-verifying identity (entering their password) and passing an anti-abuse check (reCAPTCHA). Once submitted, you have 24 hours to cancel the request directly in your account; after this period, your personal data (name, e-mail, password, profile picture, third-party account links) will be permanently anonymized and access to the account will end. Data on already-issued invoices remains retained to the extent and for the duration required by accounting and tax law (Section 7). Due to the technical nature of blockchain technology, the digital blockchain record described in Section 2 (the cryptographic (hash) coordinate fingerprint and wallet address) cannot be removed or altered once created, even as part of an account deletion; this record does not, on its own, contain directly identifying personal data.

10. Contact form

If you contact us via the form on the Contact page, we process the name, e-mail, subject, and message text you provide in order to handle your request. The form is protected by Google reCAPTCHA, which verifies the message was not submitted by automated software; this involves transferring technical data (e.g., IP address, browser behavior) to Google Ireland Limited in accordance with its own privacy policy.

11. Reviews

If you submit a customer review through the website (name or nickname, star rating, review title and text, and whether you choose to publish anonymously), we process this data to display it publicly as a testimonial once approved. Reviews are moderated before publication and are never shown automatically. If you submitted a review while logged in, it is linked to your account; if you submitted it as a guest, only the nickname you provided is stored, with no link to any account. If your review was submitted through the unique link sent after a purchase, we also record its association with that order and the fact that it comes from a verified purchase — the order's own details are never shown publicly on the review. You can request removal of a review you submitted at any time by contacting us (Art. 8).

12. Data security

We store personal data on secure servers, accessible only to authorized personnel; passwords are stored irreversibly hashed; payment data never passes through our systems (processed exclusively by Stripe); and sensitive files (Certificates) are stored on non-public storage accessible only via a unique, hard-to-guess link.

13. Children

In line with our Terms & Conditions, our services are intended exclusively for individuals 18 years of age or older. If we become aware that we have inadvertently processed personal data of a person under 18, we will delete such data without undue delay.

14. Changes to this policy

We may update this policy from time to time, in particular in connection with changes to applicable law or the scope of data processed. The current version is always available on this website.