Welcome back to GoldenLive

Enter your account details. After logging in, the system will automatically recognize whether you are a participant or a Member.

Your Cart

  • Your cart is empty!
12

PRIVACY POLICY AND TERMS OF PERSONAL DATA PROCESSING

Controller:

GOLDEN LIVE s. r. o.

Registered office: Kosorín 9, 966 24 Kosorín, Slovak Republic

Company ID: 57 820 368

E-mail: gl@goldenlive.eu

Website: www.goldenlive.eu 

Effective date: 2 August 2026

1. Introductory Provisions

GOLDEN LIVE s. r. o., with its registered office at Kosorín 9, 966 24 Kosorín, Slovak Republic, Company ID: 57 820 368, as the controller of personal data (hereinafter referred to as the „Controller“), pays due attention to the protection of personal data and respects the right of every individual to the protection of their privacy.

This Privacy Policy and Terms of Personal Data Processing (hereinafter referred to as the „Policy“) explain how the Controller collects, uses, stores, protects and discloses personal data of natural persons when using the website www.goldenlive.eu, when registering users, using services, participating in competitions and reality-show projects, voting, communicating with the Controller and during other activities related to the Controller's operations.

The Controller processes personal data in accordance in particular with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council („GDPR“),
  • Act No. 18/2018 Coll. on the Protection of Personal Data,
  • other laws and regulations of the Slovak Republic and the European Union applicable to the specific processing of personal data.

The GDPR requires an appropriate legal basis to be determined for the processing of personal data and requires the data subject to be adequately informed about the purposes, scope and other circumstances of the processing.

2. Controller of Personal Data

The controller of personal data is:

GOLDEN LIVE s. r. o.

Kosorín 9

966 24 Kosorín

Slovak Republic

Company ID: 57 820 368

E-mail: gl@goldenlive.eu

Website: www.goldenlive.eu 

The Controller determines the purposes and means of processing personal data to the extent that it acts as a controller within the meaning of the GDPR.

Data Protection Officer / DPO:
GOLDEN LIVE s. r. o.

If the Controller is not required to appoint a Data Protection Officer under the GDPR, requests concerning personal data protection may be sent to gl@goldenlive.eu.

3. Categories of Data Subjects

The Controller may process personal data primarily of the following categories of persons:

  • registered users,
  • competition participants,
  • participants in reality-show projects,
  • finalists and candidates,
  • voters,
  • website visitors,
  • persons who contact the Controller,
  • customers and payers,
  • persons who have given consent to marketing or audiovisual processing,
  • persons appearing in audiovisual materials,
  • other persons whose personal data are lawfully obtained in connection with the Controller's activities.

4. Categories of Personal Data

Depending on the specific purpose, the Controller may process in particular:

Identification Data

  • first name,
  • surname,
  • username,
  • date of birth,
  • gender,
  • other data necessary to verify identity or fulfil participation requirements.

Contact Data

  • e-mail address,
  • telephone number,
  • correspondence or billing address.

User Account Data

  • login credentials,
  • registration data,
  • user account activity data,
  • technical data related to the use of the account.

The Controller does not process passwords in readable form; when storing them, it uses appropriate security mechanisms to protect login credentials.

Audiovisual Data

  • photographs,
  • video recordings,
  • voice recordings,
  • audiovisual materials created during participation in the project,
  • publicly presented participant profile.

Technical Data

  • IP address,
  • device type,
  • operating system,
  • browser type,
  • website usage data,
  • date and time of visit,
  • data obtained through cookies and similar technologies.

Payment Data

When making payments, the Controller may process data related to the payment, its status, transaction identification and the order.

Payment data necessary to complete a payment may be processed through the payment service provider Stripe. The Controller has neither the intention nor the need to store complete payment card details if their processing is handled directly by the payment service provider.

Stripe states in its Privacy Center that it has separate personal data protection mechanisms, a DPA and rules concerning data transfers.

5. Purposes of Personal Data Processing

The Controller processes personal data according to the specific purpose.

5.1 User Registration

Personal data are processed for the purpose of:

  • creating a user account,
  • identifying the user,
  • managing the user account,
  • providing services,
  • user login,
  • communication related to the account,
  • account security.

The legal basis is primarily the performance of a contract or taking steps prior to entering into a contract pursuant to Article 6(1)(b) of the GDPR.

6. Login and Account Management

The Controller processes data necessary for user authentication and the secure operation of the user account.

This may include in particular:

  • e-mail,
  • username,
  • login credentials,
  • IP address,
  • date and time of login,
  • technical device data.

The legal basis may be the performance of a contract pursuant to Article 6(1)(b) of the GDPR and the legitimate interest of the Controller pursuant to Article 6(1)(f) of the GDPR, in particular for security purposes, prevention of account misuse and protection of information systems.

7. Monthly Payments

The Controller may process data related to paid services, subscriptions or membership fees.

The purposes of processing are:

  • processing an order,
  • recording payments,
  • providing the paid service,
  • accounting and tax records,
  • handling complaints and disputes,
  • fraud prevention.

The legal basis is primarily:

  • performance of a contract pursuant to Article 6(1)(b) of the GDPR,
  • compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR,
  • legitimate interest pursuant to Article 6(1)(f) of the GDPR in cases of fraud prevention and protection of the Controller's rights.

The payment transaction may be carried out through the Stripe service.

8. Competitions and Reality-Show Projects

The Controller may organize competitions, castings, reality-show projects and other similar activities.

As part of these activities, the following may be processed:

  • first and last name,
  • age or date of birth,
  • contact details,
  • photograph,
  • video,
  • voice,
  • participant profile,
  • data necessary to evaluate participation,
  • data necessary to organize the project.

The purposes may include in particular:

  • candidate registration,
  • participant selection,
  • organization of the competition,
  • organization of the reality-show project,
  • communication with participants,
  • evaluation of participants,
  • publication of participants as part of the project,
  • conducting voting,
  • evaluation of the competition,
  • documenting the course of the project.

The legal basis is determined according to the specific processing. Administration of participation may be based on the performance of a contract, while voluntary publication of photographs, videos or voice recordings may be based on consent.

9. Photographs, Videos and Voice Recordings

Participation in a reality-show project or another audiovisual project may involve the creation of photographs, video recordings and voice recordings.

These materials may be used in particular:

  • to present the project,
  • on the website,
  • as part of the participant's profile,
  • for public voting,
  • on social media,
  • in promotional materials,
  • in advertising campaigns,
  • when creating a project archive,
  • for broadcasting or distributing audiovisual content.

If consent is required for a specific use, the Controller will obtain it separately and in a manner allowing proof of its granting.

Consent must be specific and, where there are several different purposes, it should not automatically be considered consent to all purposes.

10. Public Participant Profiles

If the rules of a specific project allow it, the Controller may create a public participant profile.

The profile may contain, for example:

  • name or publicly used name,
  • photograph,
  • profile text,
  • video,
  • voice,
  • other data related to participation in the project.

The scope of data that will be publicly available must be communicated to the participant before publication.

11. Public Voting

The Controller may organize public voting.

The following may be processed during voting, for example:

  • user identification,
  • user account,
  • IP address,
  • technical data,
  • information about the submitted vote,
  • date and time of voting.

The data may be processed for the purposes of:

  • securing the voting process,
  • preventing repeated or fraudulent voting,
  • checking compliance with competition rules,
  • evaluating voting,
  • publishing results.

The Controller may use technical and organizational measures to prevent manipulation of voting.

12. Publication of Results

Voting results may be published on the website or through the project's communication channels to the extent determined by the rules of the specific competition or project.

If a result contains personal data of a participant, the Controller will provide the participant with appropriate information about such processing.

13. Marketing Use of Photographs and Videos

Photographs, video recordings and other audiovisual materials may be used for marketing and promotional purposes only to the extent legally permissible and about which the data subject has been informed.

If consent is the legal basis, such consent must be separate from consent required for other purposes where this is necessary due to the nature of the processing.

The data subject may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

14. Social Media

Content related to the project may be published on the Controller's social media accounts.

When publishing photographs, videos or other materials containing personal data, the Controller proceeds according to the legal basis applicable to the specific processing.

Social media platforms may independently process the personal data of their users according to their own privacy policies.

15. Contact Form

When submitting a contact form, the Controller may process:

  • name,
  • e-mail,
  • telephone number,
  • message content,
  • any other data voluntarily provided by the person.

The purpose is to handle the request, communicate with the user and address their question.

Depending on the nature of the request, the legal basis is primarily the legitimate interest pursuant to Article 6(1)(f) of the GDPR or taking steps prior to entering into a contract pursuant to Article 6(1)(b) of the GDPR.

16. Cookies

The website may use cookies and similar technologies.

Cookies may be used in particular for:

  • ensuring website functionality,
  • remembering user settings,
  • authentication,
  • analytics,
  • measuring traffic,
  • improving the user experience.

Technically necessary cookies may be used to the extent necessary to provide the requested service.

Analytical or other non-essential cookies are used in accordance with the user's settings and applicable legal requirements.

17. Google Analytics 4

The Controller uses Google Analytics 4 to analyze website traffic and usage.

Google Analytics may process technical and online identification data that enable analysis of website usage.

When using analytical cookies, the website settings and consent mechanism must be configured to comply with applicable cookie and personal data protection requirements.

Google provides Google Analytics customers with specific data processing terms and rules concerning international data transfers.

18. Legal Bases for Processing

Depending on the specific situation, the Controller uses primarily the following legal bases:

Performance of a Contract

Article 6(1)(b) of the GDPR.

It is used, for example, for:

  • registration,
  • user account management,
  • provision of paid services,
  • processing orders,
  • provision of services related to the project.

Compliance with a Legal Obligation

Article 6(1)(c) of the GDPR.

It is used, for example, for:

  • accounting obligations,
  • tax obligations,
  • document archiving,
  • fulfilment of legal obligations.

Legitimate Interest

Article 6(1)(f) of the GDPR.

It may concern, for example:

  • website security,
  • protection of user accounts,
  • fraud prevention,
  • protection of the Controller's property and rights,
  • defence of legal claims,
  • ensuring the integrity of voting.

When relying on legitimate interest, the Controller assesses whether its interest does not override the rights and freedoms of the data subject. The GDPR expressly includes legitimate interest among the legal bases.

Consent

Article 6(1)(a) of the GDPR.

Consent may be used in particular for voluntary:

  • marketing,
  • use of photographs,
  • use of videos,
  • use of voice recordings,
  • certain forms of public disclosure,
  • analytical or marketing cookies where consent is required.

Consent must be freely given, specific, informed and unambiguous.

19. Special Categories of Personal Data

In the context of reality-show and competition projects, the Controller may encounter situations where a participant provides data belonging to special categories of personal data under Article 9 of the GDPR.

This may include data concerning:

  • health status,
  • biometric data used for the purpose of uniquely identifying a person,
  • religious beliefs,
  • political opinions,
  • racial or ethnic origin,
  • sexual orientation,
  • genetic data.

The Controller will not request such data if their processing is not necessary and legally justified.

If special categories of personal data are processed, the Controller will ensure that an applicable exception under Article 9 of the GDPR exists. One possible exception is the explicit consent of the data subject, provided that the statutory conditions are met.

20. Data Obtained from Social Media

If a user provides the Controller with data through a social media platform or uses social media to interact with the project, the Controller may process data that are available and lawfully obtained in connection with such interaction.

The scope of processing is governed by the specific purpose and the rules of the relevant social media platform.

21. Recipients of Personal Data

Personal data may, where necessary, be disclosed in particular to:

  • web hosting service providers,
  • IT service providers,
  • database and cloud service providers,
  • payment service providers,
  • analytics service providers,
  • accounting and tax advisers,
  • legal advisers,
  • marketing service providers,
  • public authorities where required by law,
  • persons authorized under applicable legislation,
  • other processors whose services are used by the Controller.

The Controller discloses personal data only to the extent necessary to fulfil the specific purpose.

22. Processors

If the Controller entrusts another person with processing personal data on its behalf, it will ensure that an appropriate contractual relationship is concluded in accordance with the GDPR.

The processor may not use personal data for its own purposes beyond the applicable legal basis and contractual authorization.

23. Transfers of Personal Data to Third Countries

Some providers of technological, analytical, cloud or payment services may process personal data outside the European Economic Area.

If personal data are transferred to a third country, the Controller will ensure that such transfer is carried out in accordance with Chapter V of the GDPR.

This may include, for example:

  • an adequacy decision,
  • appropriate safeguards,
  • standard contractual clauses,
  • another legally permissible mechanism under the GDPR.

Google states in its current terms for European transfers that it provides mechanisms for cases of restricted transfers, including applicable contractual mechanisms.

24. Retention Period of Personal Data

The Controller retains personal data only for as long as necessary to fulfil the purpose for which they were collected, or for the period required by applicable law.

Indicatively, this may include:

PurposeRetention Period
User accountfor the duration of the account's existence and for a reasonable period after its deletion
Payments and accounting dataaccording to statutory accounting and tax retention periods
Contact formsfor the period necessary to process the request and subsequent communication
Security logsfor a period appropriate to the security purpose
Public profileduring participation/the project or until withdrawal of the relevant consent, if consent is the legal basis
Marketing consentuntil withdrawal of consent or according to the applicable rules
Audiovisual archiveaccording to the purpose of the project and the legal basis
Votingfor the period necessary to verify and evaluate voting and protect legal claims

Specific retention periods may be adjusted according to individual projects and the Controller's statutory obligations.

25. Security of Personal Data

The Controller adopts appropriate technical and organizational measures to protect personal data against:

  • unauthorized access,
  • unauthorized processing,
  • accidental destruction,
  • loss,
  • alteration,
  • unauthorized disclosure,
  • other misuse.

Measures may include in particular:

  • access rights management,
  • security of user accounts,
  • encrypted data transmission,
  • security updates,
  • backups,
  • monitoring of security events,
  • protection of server infrastructure,
  • restriction of access by employees and collaborators,
  • use of appropriate security standards.

26. Personal Data Breach

If a security incident occurs that may constitute a personal data breach, the Controller will take appropriate measures to investigate it, limit its consequences and remedy the situation.

Where required by the GDPR, the Controller will fulfil its notification obligations towards the competent supervisory authority and the affected data subjects.

27. Rights of Data Subjects

Under the GDPR, a data subject has in particular the right:

  • to access personal data,
  • to rectify inaccurate data,
  • to erase personal data,
  • to restrict processing,
  • to data portability,
  • to object to processing,
  • to withdraw consent,
  • not to be subject to a decision based solely on automated processing under the conditions set out in the GDPR,
  • to lodge a complaint with a supervisory authority.

The scope of individual rights depends on the specific legal basis and circumstances of the processing.

28. Right of Access

The data subject has the right to request the Controller to confirm whether their personal data are being processed and, under the conditions of the GDPR, to access such data and additional information about their processing.

29. Right to Rectification

If personal data are inaccurate or incomplete, the data subject may request their correction or completion.

30. Right to Erasure

Under the conditions set out in the GDPR, the data subject may request the deletion of their personal data.

However, the right to erasure is not absolute. The Controller may be required to retain certain data, for example, due to a legal obligation or for the purpose of establishing, exercising or defending legal claims.

31. Right to Restriction of Processing

Under the conditions of the GDPR, the data subject may request restriction of the processing of their personal data.

32. Right to Data Portability

If the conditions under the GDPR are met, the data subject may request their personal data to be provided in a structured, commonly used and machine-readable format.

33. Right to Object

Under the conditions of the GDPR, the data subject may object to the processing of personal data based on the legitimate interest of the Controller.

If personal data are processed for direct marketing purposes, the data subject has the right to object to such processing.

34. Withdrawal of Consent

If processing is based on consent, the data subject may withdraw their consent at any time.

Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Consent may be withdrawn by sending a request to:

35. How to Exercise Your Rights

The data subject may exercise their rights via:

The request should preferably include:

  • first and last name,
  • e-mail or username,
  • description of the request,
  • any other information necessary to identify the user account.

The Controller may, to a reasonable extent, request additional information necessary to verify the identity of the applicant.

According to information from the Office for Personal Data Protection of the Slovak Republic, the Controller must handle the request without undue delay and no later than one month from its receipt; under statutory conditions, the period may be extended.

36. Right to Lodge a Complaint

If the data subject believes that the processing of their personal data violates the GDPR or the laws of the Slovak Republic, they have the right to lodge a complaint with the competent supervisory authority.

The supervisory authority in the Slovak Republic is:

Office for Personal Data Protection of the Slovak Republic

The data subject has the right to contact the Office, particularly if they believe that their rights have not been respected in the processing of personal data.

37. Automated Decision-Making and Profiling

In the course of normal use of the website, the Controller may not carry out decision-making based solely on automated processing that produces legal effects or similarly significant effects on the data subject.

If such processing were introduced, the Controller would provide data subjects with information and ensure the applicable rights under the GDPR.

38. Protection of Children's Personal Data

The Controller pays increased attention to the protection of children's personal data.

If a specific service or project allows participation by minors, the Controller will ensure specific rules appropriate to the age of participants and the nature of the processing.

For online services, it is also necessary to take into account the specific rules of the GDPR and Slovak law concerning the consent of a child and the consent of a legal representative. The EDPB emphasizes the need for special protection of children and age-appropriate information.

39. Publication of Participants' Personal Data

A participant in a reality-show or competition may be publicly presented as part of the project to the extent that was communicated to the participant before the relevant processing began.

This may include in particular:

  • name,
  • photograph,
  • profile,
  • video,
  • voice,
  • voting result,
  • other content related to participation.

The scope of public disclosure must correspond to the specific purpose and legal basis.

40. Audiovisual Archive

The Controller may retain photographs, video recordings and voice recordings related to GOLDEN LIVE projects for the purposes of:

  • project documentation,
  • historical archive,
  • demonstrating the course of the competition,
  • protecting legal claims,
  • reuse of content to the extent permitted by the applicable legal basis.

If a specific use is based on consent, withdrawal of consent is assessed according to the nature of the specific use and other legal obligations of the Controller.

41. Data Minimization

The Controller undertakes to process only personal data that are adequate, relevant and necessary to achieve the specific purpose of processing.

The Controller will not request personal data merely because it could technically obtain them.

42. Accuracy of Personal Data

The Controller takes appropriate measures to ensure that personal data are accurate and, where necessary, kept up to date.

The data subject may request correction of inaccurate or incomplete data.

43. Changes to this Policy

The Controller may change or update this Policy in particular due to:

  • changes in legislation,
  • changes in technology,
  • introduction of new services,
  • changes in the way personal data are processed,
  • changes in service providers.

The current version of the Policy will be published on the website www.goldenlive.eu .

If a change would have a significant impact on the rights or obligations of data subjects, the Controller will ensure that the data subjects are adequately informed.

44. Contact Details

For questions concerning personal data protection, please contact:

GOLDEN LIVE s. r. o.

Kosorín 9

966 24 Kosorín

Slovak Republic

E-mail: gl@goldenlive.eu

45. Final Provisions

This Policy constitutes the Controller's general information documentation concerning the processing of personal data.

Specific processing conditions may be supplemented by other documents, in particular:

  • website terms of use,
  • rules of individual competitions,
  • rules of the reality-show project,
  • voting rules,
  • cookie policy,
  • marketing consent,
  • specific consent to photography and audiovisual recording,
  • agreement with the project participant.

In the event of a conflict between the general Policy and specific information provided to a participant for a particular processing purpose, the specific purpose and legal basis shall be assessed in accordance with applicable legislation.

GOLDEN LIVE s. r. o.

Effective date: 2 August 2026

Last updated: 2 August 2026