top of page

Privacy Notice and Data Processing Terms

Effective from: 17 August 2026
Version: 3.0

This is the public Privacy Notice of Rail Academy Group s.r.o. It also contains the data processing terms pursuant to Article 28 of the GDPR for cases in which the company processes personal data on behalf of a Client.

This Privacy Notice supplements the relevant provisions of the General Terms and Conditions (GTC). Reading this Privacy Notice does not in itself constitute consent to data processing.

Section 8 of this Privacy Notice becomes part of the contract upon acceptance of the GTC and, unless a separate data processing agreement has been concluded, contains the binding data processing terms between the parties pursuant to Article 28 of the GDPR.

1. Data Controller, Scope and Legal Framework

Data controller: Rail Academy Group s.r.o.

Registered office: Orechová 133, 900 42 Dunajská Lužná, Slovak Republic

Company ID (IČO): 55 333 826

Data protection contact: office@railacademygroup.com

Website: www.railacademygroup.com

This Privacy Notice applies to all services provided under the GTC.

Rail Academy Group s.r.o. acts as an independent data controller where it determines the purposes and essential means of processing for its own purposes.

Where Rail Academy Group s.r.o. acts exclusively on the documented instructions of the Client, it qualifies as a data processor. Within the same engagement, the parties’ roles may differ depending on the particular processing operation.

The applicable legislation includes in particular:

• Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
• Slovak Act No. 18/2018 Coll. on Personal Data Protection.

2. Purposes of Processing, Categories of Data and Retention Periods

Rail Academy Group s.r.o. processes personal data only for specified, explicit and lawful purposes and only to the extent necessary for the relevant purpose.

Processing may relate in particular to:

• establishing contact and concluding contracts;
• providing educational and consulting services;
• operating online systems;
• invoicing and accounting;
• handling complaints and legal claims;
• marketing activities where an appropriate legal basis exists;
• making photographs, audio recordings or video recordings;
• recruitment.

Depending on the relevant purpose, the categories of personal data processed may include:

• identification and contact details;
• employer- and job-related information;
• contractual and invoicing data;
• training and attendance records;
• examination and assessment data;
• certificate-related information;
• project and communication data;
• technical and system usage logs.

Depending on the relevant activity, the legal basis for processing may be Article 6(1)(a), (b), (c) or (f) of the GDPR, including in particular:

• the data subject’s consent;
• performance of a contract or steps taken prior to entering into a contract;
• compliance with a legal obligation;
• the legitimate interests of Rail Academy Group s.r.o. or a third party.

Legitimate interests may include, in particular, business communication, the secure operation of services and the establishment, exercise or defence of legal claims.

Rail Academy Group s.r.o. retains personal data only for as long as necessary to fulfil the relevant purpose of processing.

When determining the retention period, it takes particular account of:

• the duration of the service and the contractual relationship;
• applicable training and examination requirements;
• accounting and tax requirements;
• applicable limitation periods;
• the need to establish, exercise or defend legal claims.

Personal data is deleted once the purpose of processing has ceased to exist and the applicable retention period has expired.

Before or at the time personal data is collected, the data subject is informed of the specific purpose of the processing, the categories of data concerned, the legal basis and the applicable retention period.

Where personal data has not been obtained directly from the data subject, the relevant information is provided at the time specified in Article 14 of the GDPR. As a general rule, this takes place within a reasonable period after obtaining the data, but no later than one month thereafter, or at the latest when the data subject is first contacted or the data is first disclosed.

Rail Academy Group s.r.o. provides more detailed information at the data subject’s request.

3. Sources of Data, Provision of Data and Special Categories of Data

Personal data may be obtained from:

• the data subject directly;
• the Client or the data subject’s employer;
• an instructor, examiner or consultant;
• a project partner or cooperating organisation;
• a public authority;
• an earlier document;
• the information system used for the relevant service.

If data required for the performance of a contract or compliance with a legal obligation is not provided, the relevant service may be unavailable or may only be provided to a limited extent.

4. Recipients and Data Processors

Personal data may be disclosed, only to the extent necessary, to:

• the Client or the data subject’s employer;
• an instructor, examiner, consultant or project partner;
• a cooperating training, certification or expert organisation;
• an accountant or a provider of legal or insurance services;
• a bank or payment service provider;
• a public authority or court acting under applicable law.

The data protection role of instructors, examiners and consultants depends on the particular assignment.

Where they act on the instructions of Rail Academy Group s.r.o., they are subject to data processing and confidentiality obligations. Where they independently determine the purposes and means of processing based on their own statutory or professional responsibilities, they act as independent data controllers.

Key IT Service Providers
Microsoft

Service: Microsoft 365, Exchange Online, Office and Teams.

Location of processing: Microsoft data centres located in the EU or EFTA. Limited global support or security access may be possible.

Safeguards applied: Microsoft Data Protection Addendum (DPA), EU Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.

Moodle Pty Ltd

Service: MoodleCloud online learning platform.

Location of processing: the selected EU region using Amazon Web Services infrastructure in Ireland. Moodle’s contractual subprocessors may also be involved in processing subscription data.

Safeguards applied: Moodle’s data processing terms and Standard Contractual Clauses (SCCs) for processing outside the European Economic Area.

Wix.com Ltd

Service: website and hosting services.

Location of processing: Israel, Ireland, the United States and the locations in which Wix’s published subprocessors operate.

Safeguards applied: an EU adequacy decision for Israel; Standard Contractual Clauses (SCCs) and supplementary safeguards for other countries not covered by an adequacy decision.

The above list contains the permanent, material and direct IT data processors used by Rail Academy Group s.r.o.

5. Transfers to Third Countries

Personal data may be transferred outside the European Economic Area only in accordance with the conditions set out in Chapter V of the GDPR.

Such a transfer may be based in particular on:

• an adequacy decision adopted by the European Commission; or
• appropriate safeguards pursuant to Article 46 of the GDPR, including the Standard Contractual Clauses (SCCs).

The data subject may request information about a particular transfer and a copy or summary of the applicable safeguards by contacting office@railacademygroup.com.

6. Data Security

In accordance with Article 32 of the GDPR and Section 39 of Slovak Act No. 18/2018 Coll., Rail Academy Group s.r.o. implements, and requires its service providers to implement, technical and organisational measures appropriate to the nature of the processing, the systems used and the risks identified.

Depending on the particular system and its technical capabilities, these measures may include:

• role-based access limited to what is necessary for the relevant task;
• revocation of access rights that are no longer required;
• multi-factor authentication for administrator and other privileged accounts where supported by the system;
• encrypted data transmission;
• encryption at rest provided by the cloud service provider.

Upon a justified request, Rail Academy Group s.r.o. provides more detailed information about the security measures applied to a particular service or information system.

7. Data Subject Rights and Remedies

Subject to the conditions set out in Articles 15–22 of the GDPR, the data subject may:

• request access to and a copy of their personal data;
• request rectification of their personal data;
• request erasure of their personal data;
• request restriction of processing;
• exercise the right to data portability;
• object to processing based on legitimate interests;
• withdraw previously given consent at any time.

Under the conditions set out in Article 22 of the GDPR, the data subject also has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.

The right to erasure does not override mandatory retention obligations or processing required for the establishment, exercise or defence of legal claims.

Requests concerning data subject rights may be submitted to office@railacademygroup.com.

As a general rule, Rail Academy Group s.r.o. responds within one month of receiving a request. In the case of complex or multiple requests, this period may be extended by a further two months, subject to appropriate justification.

Rail Academy Group s.r.o. does not use solely automated decision-making or profiling that would produce legal effects concerning a data subject or similarly significantly affect them.

Supervisory Authority

Úrad na ochranu osobných údajov Slovenskej republiky
Galvaniho Business Centrum II
Galvaniho 7/B
821 04 Bratislava
Slovak Republic

Website: www.dataprotection.gov.sk

8. Data Processing Terms for Clients
8.1. Applicability and Description of Processing

This section applies where Rail Academy Group s.r.o. processes personal data on behalf of the Client as data controller and in accordance with the Client’s documented instructions.

The subject matter of the processing is the provision of services under the GTC. The duration of processing corresponds to the duration of the contract and the time required for the proper return or deletion of the data.

Processing operations may include:

• receiving and recording data;
• organising and storing data;
• using or disclosing data;
• restricting processing;
• returning or deleting data.

Data subjects may include:

• the Client’s contact persons;
• the Client’s employees and contractors;
• applicants, participants and examination candidates;
• consultants and project partners.

The categories of data processed may include:

• identification and contact details;
• employer- and job-related data;
• training and attendance records;
• performance, examination and certification data;
• project and document data;
• communication data;
• technical log data.

Special categories of personal data within the meaning of Article 9 of the GDPR may be transferred only on the basis of a separate written agreement.

8.2. Obligations of the Client

The Client:

• ensures the lawfulness of processing, an appropriate legal basis and proper information of data subjects;
• provides only accurate, up-to-date and necessary personal data and warrants that it is entitled to disclose such data;
• issues lawful, clear and documented instructions;
• assesses data subject requests and fulfils the regulatory obligations incumbent on the data controller;
• provides advance notice of planned processing involving high risks or special categories of personal data.

Within a data processing relationship, documented instructions may be issued only by the Client acting as data controller.

Data subjects may exercise the rights set out in Section 7 of this Privacy Notice. Where a decision on a request falls within the Client’s responsibility, Rail Academy Group s.r.o. forwards the request to the Client without undue delay.

8.3. Obligations of Rail Academy Group s.r.o.

Rail Academy Group s.r.o.:

• acts only on the Client’s lawful and documented instructions;
• informs the Client without undue delay if, in its opinion, an instruction infringes the GDPR or another applicable provision of EU or Member State data protection law;
• deviates from the Client’s instructions only where processing is required by EU or Member State law and informs the Client of that legal requirement in advance, unless such information is prohibited by law for important reasons of public interest;
• ensures that persons authorised to access personal data are bound by confidentiality obligations;
• applies the security measures described in Section 6 of this Privacy Notice;
• provides reasonable assistance in handling data subject requests, personal data breaches, data protection impact assessments and consultations with supervisory authorities;
• makes available to the Client the information necessary to demonstrate compliance with Article 28 of the GDPR;
• returns or deletes the data, at the Client’s choice, when the service ends, except where mandatory retention requirements apply.

8.4. Subprocessors and International Transfers

The Client grants general written authorisation for the engagement of the subprocessors identified in Section 4 of this Privacy Notice and any additional subprocessors communicated in advance in connection with the relevant service.

Subprocessors are subject to data protection obligations that are at least equivalent to those applicable to Rail Academy Group s.r.o. Rail Academy Group s.r.o. remains liable to the Client for the performance of the subprocessor’s obligations.

Transfers outside the European Economic Area are subject to the conditions and safeguards set out in Section 5 of this Privacy Notice.

8.5. Personal Data Breaches, Audits and Cooperation

Rail Academy Group s.r.o. notifies the Client without undue delay of any personal data breach affecting personal data processed on the Client’s behalf.

Based on the information available to it, Rail Academy Group s.r.o. communicates:

• the nature of the breach;
• the categories of personal data and data subjects concerned;
• the likely consequences of the breach;
• the measures taken or proposed.

The Client decides whether the supervisory authority and the data subjects must be notified. Rail Academy Group s.r.o. provides reasonable assistance in this regard.

The Client is entitled to verify compliance with applicable data protection requirements. Rail Academy Group s.r.o. may primarily demonstrate compliance through documents, service-provider certifications or audit reports.

An on-site audit or an audit requiring access to systems may be conducted no more than once per year, during working hours, upon reasonable prior notice and subject to the protection of other clients’ data and business secrets.

The annual limitation does not apply in the event of a personal data breach or an order from a supervisory authority.

8.6. Return and Deletion of Data

Upon termination of the contract, Rail Academy Group s.r.o., at the Client’s documented choice, returns or deletes all personal data processed on behalf of the Client, including existing copies, unless retention is required by EU or Member State law.

Personal data stored in active systems is deleted without undue delay.

This does not affect data that Rail Academy Group s.r.o. processes separately as an independent data controller on the basis of a demonstrated legal basis.

9. Cookies, Confidentiality and Amendments to this Privacy Notice
9.1. Cookies and Similar Technologies

The website uses the Usercentrics for Wix consent-management interface integrated into the Wix system to manage cookies and similar technologies.

Services requiring consent are activated only after the visitor has given prior consent.

Through the consent-management interface, visitors may:

• accept or reject services that require consent;
• configure individual settings by category;
• view the services used and the related data processing information.

Consent may be modified or withdrawn at any time using the “Privacy Settings” button that is continuously available on the website.

9.2. Confidentiality

Irrespective of personal data protection requirements, Rail Academy Group s.r.o. and the Client treat all non-public business, technical, financial, organisational and professional information obtained during the provision of services as confidential.

Access to such information is granted only to persons who require it for the performance of their tasks.

9.3. Amendments to this Privacy Notice

Rail Academy Group s.r.o. may amend this Privacy Notice, in particular in the event of:

• changes in legislation;
• the introduction of a new processing activity;
• a change of service provider;
• technical or organisational changes.

The current version of this Privacy Notice is available on the website together with its effective date and version number.

The Client will be informed separately and in due time of any material amendment to the data processing terms pursuant to Article 28 of the GDPR.

This Privacy Notice must be interpreted together with the GTC in force, the accepted quotation, the order and any individual service agreement.

In matters relating to data processing, the mandatory provisions of data protection law and the specific data processing terms contained in this Privacy Notice apply.

bottom of page