Skip to content AgencyRadar 
Sign in

Privacy & data protection

The data controller is Webikon s. r. o., Vápenná 15, 821 04 Bratislava, company ID 46809422 ("we"). Data-protection contact: info@agencyradar.eu. This policy has two parts: A. website visitors and customers and B. persons whose data appears in the agency catalog (the Art 14 GDPR notice).

A. Visitors and customers

Cookies and analytics

The site uses no analytics or marketing cookies and no third-party trackers — which is why there is no cookie banner. The only cookies our application sets are strictly necessary and only appear once you sign in: ar_pro (Pro license sign-in, 30 days) and, for the operator, ar_admin. Separately, our hosting layer (Cloudflare) may set its own strictly-necessary security cookies on some requests — such as __cf_bm for bot mitigation — which protect the site, expire quickly, track nothing across sites, and are likewise exempt from consent. We also use the browser's local storage for your in-progress comparison and theme — that data never leaves your browser.

We measure usage with our own tool — no cookies, no third parties: we record the event type (e.g. "profile viewed", "filter applied") and its parameters — on arrival also the referring site's domain (never the full address), and the time spent on the page. Nothing is stored on your device and nothing is read from it: the measurement carries no screen size, no performance metrics and no other device characteristic — only what any ordinary web server learns from a visit (the page, the referring domain, how long it stayed open). We never store your IP address or user agent — daily visitor counts come from a salted fingerprint (hash) that changes every day, so activity cannot be linked across days or attributed to a person. We honor the Do Not Track and Global Privacy Control signals (the event is counted without any fingerprint). Legal basis: legitimate interest in improving the service (Art 6(1)(f) GDPR). The fingerprint is pseudonymous rather than anonymous: within a single day it groups events from the same browser, but because we store neither the IP address nor the user agent and the salt rotates daily, we cannot attribute it to a person or connect it to any other day. You can switch measurement off below.

Two specifics that belong with the above. What you type in the search box is one of those parameters, shortened to 80 characters — we drop it before storing if it looks like an e-mail address or a phone number, because that is personal data rather than a market signal. And these event records are kept for 400 days, so a year-on-year comparison is possible, then deleted automatically. Aggregated demand — which services and places are searched for, including search terms that returned nothing — is part of what Business-tier customers receive where that tier is sold (see the terms), but only where at least three different visitors used the same term, so no single visitor's search can appear.

Switch this off and this browser stops sending the anonymous beacon described above. The choice is stored in this browser only, needs no account, and costs nothing. We also honour your browser’s Do Not Track / Global Privacy Control signal.

Server logs

Operating the site produces standard request logs (IP address, time, URL) at our hosting provider's edge, for security and debugging — legal basis: legitimate interest (Art 6(1)(f) GDPR). These are Cloudflare's own logs under its retention policy, not a table we keep: the site's own database holds no request log. Cloudflare states a maximum of 90 days for them.

For a Pro licence (including the free one) we do keep a daily per-licence summary: how many requests it made, how many records were delivered to it, how many requests were refused, and the highest paging offset it reached on that UTC day. This is not a request log — it holds no IP address, no URL and no individual request, only the day's totals. Two purposes: performing the contract (the tier's daily limits — Art 6(1)(b) GDPR) and protecting the catalogue against the bulk copying that section 5 of the terms forbids (legitimate interest — Art 6(1)(f) GDPR). The summaries are deleted after 400 days. If a licence crosses the configured thresholds the system alerts the operator, and the service may temporarily reduce its page size or pause bulk export until the next UTC midnight (section 7 of the terms).

Hosting and bot protection (Cloudflare)

The site runs on infrastructure operated by Cloudflare, Inc. (USA), which as our processor technically handles the network data of every request (IP address, headers) to deliver the page, protect against overload and enforce rate limits. Our forms (suggest an agency, report data and objections, message to an agency, data-protection complaint, registration, license activation) are protected from bots by Cloudflare Turnstile, which processes your IP address and technical browser characteristics during verification; it uses no tracking cookies and does no cross-site profiling. Legal basis: legitimate interest in secure and available operation (Art 6(1)(f) GDPR). Cloudflare is certified under the EU-U.S. Data Privacy Framework, which safeguards any transfer of data to the USA (Art 45 GDPR).

Map tiles (OpenFreeMap)

On pages with a map we load map tiles from OpenFreeMap (operated by Hyperknot Software Kft., Hungary – EU). Displaying the map necessarily transmits your IP address to that service; per its policy OpenFreeMap uses no cookies and does not log IP addresses persistently. Legal basis: legitimate interest in the functional map you requested by opening the page (Art 6(1)(f) GDPR). The transfer stays within the EU.

Feedback forms (report data, suggest an agency)

We process the message content, an optional e-mail and the IP address (spam protection). Legal basis: legitimate interest in data quality. We delete the IP address after 90 days in every case, with no exception. Your e-mail address also goes after 90 days — unless the report is an objection, a correction request or a data-protection complaint, in which case we keep it until we have resolved the report, and for 30 days after that so a mistakenly closed report can still be answered; at most 24 months from receipt either way. The report text itself is kept as an anonymous data-quality record.

Message to an agency (relayed contact)

Where a record’s contact details are withheld because they are an individual’s personal data, the profile offers a “Write a message” form. We process the message text, your e-mail (required — the agency replies to it directly), an optional company name and budget, and the IP address (spam protection). The recipient of your message and e-mail is the agency you are writing to; a member of our staff passes it on, and we do not give you the agency’s contact details in return. Legal basis: your consent given on submission (Art 6(1)(a) GDPR), which you can withdraw until the message is handed over by e-mailing info@agencyradar.eu. We delete your e-mail address and IP after 90 days; the message text is kept as an anonymised record.

Pro customers

For an order we process the company name, company ID (IČO), billing e-mail and license data — legal basis: performance of a contract (Art 6(1)(b)) and legal obligations (accounting — 10 years). Card payments are processed by Stripe as an independent controller; we never see card numbers. Daily API request counts are kept to enforce limits.

If you register for the free tier we process your e-mail, optional name and business name, your country, and the licence record itself — legal basis: performance of the licence terms (Art 6(1)(b) GDPR). Occasional product news is sent only if you asked for it at registration (consent, Art 6(1)(a)); you can withdraw at any time via the link in each message or by e-mail.

B. Data in the agency catalog (Art 14 GDPR notice)

The catalog contains data about companies, which is not personal data — and alongside them it lists self-employed sole traders and freelancers, whose records ARE personal data, as are the named e-mail addresses and phone numbers of contact persons. We process this data on the basis of our legitimate interest in operating a business directory of the agency market (Art 6(1)(f) GDPR — the purpose below); it comes from public registers and from the traders' own public websites. Sole traders' records carry additional safeguards, applied automatically in the data pipeline: an address that is also a home (a natural person's registered place of business) is never published — not on the site, not in the API, not in exports; a freelancer's named (non-generic) e-mail address and phone number are neither displayed nor exported, and interested buyers are pointed to their public website instead; and objection, rectification and erasure follow the "Your rights" and complaints procedures below in full.

  • Categories: business name, company ID, registered office, financial indicators from public statements, website, services and technologies offered, references and published contact details (e-mail, phone).
  • Sources: Slovak Register of Financial Statements (registeruz.sk), Register of Legal Entities (Statistical Office of the SR), Financial Administration of the SR (opendata.financnasprava.sk), Business Register of the SR (orsr.sk), Registr smluv (data.smlouvy.gov.cz), ARES (Czech business register), Czech VAT-payer register — unreliable-payer flag (adisrws.mfcr.cz), GitHub (github.com), Pretlak (pretlak.com), Na volné noze (navolnenoze.cz), Agency websites and public directories. Every profile lists its own sources.
  • Purpose and legal basis: market transparency, verification of business partners and matching demand with supply of agency services — legitimate interest under Art 6(1)(f) GDPR.
  • Retention: while the entity remains in the source registries and active on the market; we refresh from sources and delete data whose source record has ceased to exist.
  • Recipients: website visitors; Pro export/API customers as independent controllers, whose contracts require compliance with the direct-marketing rules of this market — CZ contacts must not be sent unsolicited marketing e-mail without consent (§ 7 z. 480/2004 Sb.); SK company contacts may be used for related B2B offers with an opt-out (§ 116 z. 452/2021 Z. z.). The export itself already withholds the contacts that rule protects, and flags the rest. A named person's e-mail address is not included in any export, API response, MCP result or paid report until we have sent that address its individual Art 14 notice — the profile page may publish it where the local rule permits, but handing it to a paying customer waits for the notice.
  • Automated decision-making: none. Transfers out of the EU: only within the technical hosting layer (Cloudflare, the EU-U.S. Data Privacy Framework — see part A).

Your rights and data removal

You have the right of access, rectification, erasure, restriction, portability and objection under Art 21 GDPR — easiest by e-mail to info@agencyradar.eu or via the "Report data or object" form on a profile. We respond within one month. An objection to the use of contact details for direct marketing is always honored without further assessment; removed or withheld data goes on an internal suppression list — recorded against the company's registry identifier, without your name or contact details — so registry refreshes and re-imports cannot bring it back. For factual registry data of legal entities we offer correction; there is no legal claim to its erasure (registry publicity, CJEU Manni C-398/15) — but we assess every request individually. You may complain to Úrad na ochranu osobných údajov SR (the Slovak DPA) or Úřad pro ochranu osobních údajů (the Czech DPA).

Complaints about how we handle your data

You can complain to us electronically about our handling of your personal data: Data-protection complaint. We acknowledge receipt in writing within 30 days and write to you with the outcome within one month of receiving it (Art 12(3)). You do not need to be listed in the catalog to use it. This does not affect your right to complain directly to Úrad na ochranu osobných údajov SR (the Slovak DPA) or Úřad pro ochranu osobních údajů (the Czech DPA) — you do not have to come to us first.

Version: September 2026.