Legal
Privacy policy
What JER collects when you use JER ImmoX, the customer panel or this website, why it is collected, how long it is kept and what you can ask us to do about it.
Last updated 18 August 2026/Version 1.1
In short
- This website sets no cookies of its own and runs no analytics, tracking or profiling of any kind.
- Fonts, images and scripts are served from this domain, so no third party sees your visit.
- Nothing here decides anything about you automatically.
- An account stores your name, email, billing details and the history of the operations you have run.
- Files you upload are processed to produce the result and are not used for anything else.
- We do not sell personal data and we do not share it for advertising.
- You can ask for a copy of your data or for your account to be deleted at any time.
1. Who is responsible
The controller of your personal data is JER, a sole trader in the Slovak Republic:
- Trade name: Ján Zamkovský - JER, trading as JER ImmoX
- Place of business: Družstevná 47, 059 01 Spišská Belá, Slovak Republic
- ICO: XX-DOPLNIT-XX · DIC: XX-DOPLNIT-XX
- Entered in the Živnostenský register Okresného úradu Kežmarok, no. XX-DOPLNIT-XX
- Email: [email protected]
No data protection officer is appointed. We are not required to appoint one: we are not a public authority, our core activity is not large-scale monitoring, and we do not process special categories of data on a large scale. Everything in this policy, including any request about your rights, goes to [email protected].
2. This website
jerimmox.com is a static site. It sets no cookies of its own, uses no analytics, no advertising pixel, no consent banner and no third-party script. Fonts and images are served from this domain rather than a content network, which is deliberate: a font CDN would see the IP address of every visitor. Nothing is written to local storage.
The one exception is security. The site sits behind Cloudflare, and where Cloudflare has to verify that a connection is not automated it may set a short-lived cookie (__cf_bm, cf_clearance). These carry no advertising, analytics or profiling function. They are strictly necessary to deliver the service you asked for, so under section 109(8) of Act 452/2021 on electronic communications they do not require consent, which is why there is no cookie banner on this site.
The web server keeps ordinary access logs containing the IP address, the time, the page requested, the referrer and the browser identification. These exist to keep the service running and secure, on the basis of our legitimate interest under Article 6(1)(f) GDPR, and are deleted or aggregated within 30 days. The site sits behind Cloudflare, which also processes the connection to filter attacks and reduce load.
The download button reads the current version from my.jerimmox.com. No personal data is sent with that request.
3. Your account
When you register at my.jerimmox.com we process:
- Identity and contact: name, surname, email address.
- Billing details: business or personal name, address and, if you have one, a VAT identification number.
- Account state: token balance, purchases, whether unlimited access is active.
- Usage: which operation was run on which module, when, and what it cost.
- Security: the password as a hash and never in readable form, verification codes, sign-in times, sessions and the IP address of a sign-in.
The basis for this is performance of the contract between us, Article 6(1)(b) GDPR, and for the security records our legitimate interest in preventing account abuse, Article 6(1)(f).
4. Files you upload
An operation needs the file you read from the unit. It is processed to produce the result you asked for. We do not use uploaded files to build any other product, do not share them and do not attempt to identify a vehicle or its owner from one.
A file usually contains a VIN and other vehicle identifiers. Where a vehicle can be linked to a person, that is personal data, and it is processed only to carry out the operation you requested. Working files are removed once the job is complete; the record that an operation happened is kept in your history, and where an operation depends on remembering a unit, the identifier of that unit is retained so that you are not charged twice for it.
Do not send us files or documents that contain personal data we do not need. If you attach something to a support message, send only what is needed to answer the question.
5. Email
We send transactional email: verification codes, password resets, receipts and notices about the service. These are part of the contract and cannot be turned off while the account exists. We do not run a marketing mailing list. If that changes it will be opt-in and separately consented to.
6. Who else processes it
We use a small number of processors, each under a data processing agreement and only for the purpose stated:
- Hosting in the European Union, for the servers that run the service.
- Cloudflare, for protection against attack and for delivery of this site.
- Email delivery, for the transactional messages above.
- Payment processing, which handles the payment itself. Card details are entered with the payment provider and never reach our servers.
We do not sell personal data, and we do not share it for advertising or profiling. We disclose data to an authority only where a valid legal obligation requires it.
7. Transfers outside the EU
Our servers are in the European Union and your account data is held there.
Cloudflare, Inc. is established in the United States and is the one processor that routinely handles data outside the European Economic Area, namely the connection metadata described in section 2. That transfer rests on the European Commission's standard contractual clauses together with Cloudflare's supplementary measures, and Cloudflare is certified under the EU-US Data Privacy Framework. Where any other processor operates outside the EEA, the transfer is covered by the standard contractual clauses or by an adequacy decision, and you may ask us for a copy of the safeguards that apply.
8. How long it is kept
- Account and usage history: while the account exists, and then removed within 90 days of deletion.
- Invoices and payment records: as long as accounting and tax law requires, which in the Slovak Republic is generally ten years. This obligation overrides a deletion request for those documents.
- Web server logs: 30 days.
- Working copies of uploaded files: removed once the operation is complete.
9. Do you have to give us this data
Only what the contract needs. Name, email, billing details and a password are required to open and run an account: without them we cannot create the account, take payment or issue an invoice, so the service cannot be provided. That is a contractual requirement, not a statutory one.
The file you upload is required only for the operation you asked for. Not uploading a file simply means that operation does not run; the account is unaffected. There is no obligation to give us anything beyond this, and we ask for nothing beyond it.
10. Automated decisions and profiling
There are none. No decision about you is made solely by automated processing within the meaning of Article 22 GDPR, and we do not profile you. Deducting tokens after an operation is the execution of a price you were shown, not a decision about you. Suspending an account for suspected unlawful use is decided by a person.
11. Your rights
Under the GDPR you may ask for access to your data (Article 15), correction of it (16), deletion of it (17), restriction of processing (18), a portable copy (20), and you may object to processing based on legitimate interest (21). You may withdraw consent where processing rests on consent, without affecting what was done before. Exercising these rights is free.
Write to [email protected]. We answer within one month, and tell you if we need to extend that. Deleting an account can also be done from the customer panel.
If you believe we have handled your data unlawfully you may complain to the supervisory authority. In the Slovak Republic that is:
- Úrad na ochranu osobných údajov Slovenskej republiky
- Hraničná 12, 820 07 Bratislava 27, Slovak Republic
- [email protected] · dataprotection.gov.sk
If you live in another EU or EEA country you may complain to the supervisory authority there instead.
12. Security
Traffic is encrypted in transit. Passwords are stored as hashes, never in readable form. An account signs in on one computer at a time, and a password change ends every existing session. Access to production data is limited to what is needed to run the service.
No system is perfectly secure. If a breach is likely to result in a risk to your rights we will notify the supervisory authority and, where the risk is high, you.
13. Children
The service is for professional and adult use. It is not directed at children and we do not knowingly process the data of anyone under 16.
14. Changes
We may update this policy. The current version is the one on this page, dated at the top. Where a change materially affects you we give notice in the customer panel or by email.