Our commitment: the safety of your personal data comes first.
When you visit our online shop and use the online shop services, we collect and process your personal data, which allows you to see our offer, select, purchase, and order the delivery of our goods, and it also provides you with a quick, pleasant, and safe online service.
Personal data will be collected, processed, and kept pursuant to the personal data protection regulations and this Policy.
Your personal data, its collection and use are an inseparable part of the Terms and Conditions for the Operation of Our Online Shop and can only be fully interpreted in relation to them; therefore, we recommend that you read them in their entirety.
Personal data controller
The Controller is the company Pivovarna Laško Union d.o.o., Pivovarniška ulica 2, 1000 Ljubljana.
If you have any questions, please e-mail us at email@example.com.
How do we obtain, use, or otherwise process your personal data?
We obtain your personal data when you provide them to us, e.g. when:
- you sign up as a user,
- submit an order,
- cancel an order,
- review our contents,
- you pose various questions, return tickets,
- you communicate with us over social media,
- when you subscribe to our news and notifications regarding our services.
Technical data are obtained automatically.
Which types of personal data are collected or obtained?
You use our services as:
- an non-registered user (guest)(in this case, your data will be collected through cookies after you provide your consent when you visit our pages, with the purpose of providing better functionalities and user experience, safety, the counting of website traffic, and ensuring the smooth functioning of the webpages),
- a registered user (member),
- a buyer.
We collect various types of personal data regarding our registered users and buyers:
- identity data: name, surname, e-mail address, and a password, which is encrypted and only known to the user (it will also not be known by us or revealed to us).
- data regarding the representative of the legal entity,who has submitted an order or performed a purchase and other actions in the web shop on behalf of a legal entity;
- contact data: e-mail address, billing address, and phone number.
- financial data:we do not keep data regarding your credit cards. These data are only provided to the issuer of your credit card. The same applies to other similar forms of online payment.
- data regarding purchases and payments: we keep all of the data regarding your orders and payments, including data on payment cancellation and returns. You can see and edit these data on your web shop profile.
- data related to your use and your profile:the last viewed items, products in a non-finalized order, frequency of visiting particular sections, frequent purchases, communication with us.
- marketing data:your subscriptions to our e-publications.
- technical data: in order to ensure safety and demonstrability, IP addresses, operational system data, browser data, device location data, the type of the device used to access our website, etc. are also collected.
How do cookies work in our online shop?
For what purposes are personal data processed and used?
We mainly use your personal data for one or more of the following reasons:
- In connection with your use of our services, e.g. to fulfil your orders, deliver goods, etc.
- To respond to your questions or claims, which you sent to us via contact forms, e-mail addresses posted on the website, or via our social media profiles.
- Online behavioral advertising (profiling). On some of the pages on our website, we can collect and/or allow third persons (advertising partners) to collect (using online monitoring tools, such as cookies and other tracking and monitoring technologies) personal data referring to your activities on these pages.
- For advertising purposes regarding our services, news, and event organization.
When we process your personal data on the basis of your permission, you can cancel your permission at any time by sending a cancellation request to the following e-mail address: firstname.lastname@example.org. The effective date of such cancellation is 30 days after receiving your request.
Personal data are also processed for purposes representing our legitimate interest, namely in the following cases:
- When personal data are provided to our associated company Pivovarna Laško Union Online, spletna trgovina, d.o.o., Pivovarniška ulica 2, 1000 Ljubljana, which fulfils online orders and carries our online payments in accordance with our internal administrative purposes (preliminary note 48 of the GDPR).
- When we protect our operations and business interests, including with the purpose of verifying credit and past experiences, preventing fraud, and collecting debt.This is important for the protection of our legitimate interests in preventing criminal activities, such as fraud or money laundering, for ensuring that our website and our services are not abused, and for protecting our operations. Such verifications will only be performed if permitted by law.
- When we communicate with our business consultants and legal representatives.This is necessary for our legitimate interest in obtaining legal or expert business advice; we will, however, only forward your personal data if necessary, to a minimum extent and in anonymous form, whenever possible.
- When we manage and improve our websites, including by adjusting the user experience on our website. This is necessary for our legitimate interest to better understand the wishes of our users and potential buyers and to adjust our websites, products, and services depending on your needs and wishes.
- When we enforce our legal rights and for the purpose of observing laws, regulations, and other statutory requirements. This is necessary for our legitimate interest in protecting our operations and enforcing our legal rights and for ensuring the physical, network, and information security and integrity. Furthermore, it is necessary for our legitimate interest in ensuring a safe IT system and networks, including backing up and archiving, preventing malware, viruses, errors, or other harmful codes, and preventing unauthorised access to our systems and all forms of attacks or damage to our IT systems and networks.
- In connection with disclosure orders and in the event of selling or buying a company and/or assets, either actual or potential. This is necessary for our legitimate interest in selling and/or ensuring and promoting the success of our operations.
- For statistical and research purposes. The data will be rendered anonymous and used for our legitimate interests in processing personal data for research purposes, including marketing research, the better understanding of our customers, and tailoring our products and services to your needs.
Who do we forward the personal data to?
In addition to us, your personal data can also be used by our contractual partners and affiliated entities who are needed for the performance of our services:
- the companies which maintain, update, and edit our website and related services on our behalf,
- our legal advisers, provided that they assist us in treating your questions or requests,
- payment systems (e.g. Stripe, Paypal, Minimax),
- authorized institutions if required by law (court etc.),
- we forward your data to third parties with your consent.
All partners who have access to personal data are committed to handling personal data carefully and in accordance with the law. We only provide them with data that are necessary to successfully fulfil an order, carry our a sales process, or other activities. In no case are your personal data provided to unauthorised third parties.
How long are your personal data processed?
If you would like to obtain more information on where your personal data are stored and how long they will be stored as well as on your right to erasure and data portability, please e-mail us at: email@example.com.
What are my rights regarding personal data?
We provide all of the necessary support to our buyers and users when enforcing the rights listed below:
- being informed of all of the forms of using personal data,
- having insight into all of the data collected about you,
- in certain cases, you can also enforce your right to have your personal data be erased. If you have signed up as a user, but have never submitted an order, then we can erase you upon your request. However, if you have made purchases, we ask that you take into account that your data must be kept in accordance with the law,
- at your request, we will provide you your personal data collected in electronic form,
- we will process your objections to the processing of your personal data,
- you may object to the use or the processing of your personal data when they are used or processed in order to be able to perform a task carried out in public interest if your personal data are processed for our legitimate interests, including "profiling" (e.g. predicting your behavior on the basis of your personal data) on the basis of any of these purposes,
- you may object to the processing of your personal data for the purposes of direct marketing (including any automated assessment that is carried our about your or any of your characteristics, provided that they are related to such direct marketing) by e-mailing us at firstname.lastname@example.org requesting to stop selling you marketing messages. Please state the type of messages from which you wish to unsubscribe.
You may enforce all of your other rights by notifying us regarding your request in writing or by emailing us at: email@example.com with the subject Personal data – "subject", whereby the subject may be one of the rights provided: access, completion, rectification, restriction of data processing, blocking data processing, personal data erasure, objection to data processing, data transfer.
Whenever we intend to use your personal data for a new purpose, we will provide you with the information regarding this purpose and all other relevant information before we use your personal data for this new purpose.
If you think that your personal data are stored or otherwise processed contrary to the applicable regulations governing personal data protection, you have the right to file a complaint with the Information Commissioner of the Republic of Slovenia.
Transmitting data to third countries
The Controller does not usually export personal data to third countries. In cases when the Controller's suppliers are from third countries and when they perform their services for the Controller or the users, personal data processing can occur and the owner of the service enables this taking into account the terms and conditions set forth by the General Regulation (GDPR) – particularly by using appropriate procedural safeguards pursuant to the General Regulation – GDPR.
When your personal data are transmitted outside of the European Economic Area, we will do this after first performing a careful inspection of the appropriate legal bases and safeguards, such as: data protection policies known as "Binding Corporate Rules" or "BCR's", standard contractual clauses adopted by the European Commission or the Information Commissioner and confirmed by the European Commission pursuant to the appropriate law, code or codes of conduct drafted by an association or another authority approved by the Information Commissioner, approved certification mechanisms (such as the EU-US Privacy Shield), or when permitted by the Information Commissioner or the contractual clauses between the Controller or Data Processor and the personal data controller, processor, or recipient in a third country or international organization.
Changes to your personal data
Please inform us of any changes to your personal data that we have about you, so that these data can always be accurate and up-to-date.
Non-transmission of data and consequences
When providing online shop services, the Seller only requires the data that is necessary to perform these services or to enter into a contractual relationship for the sale of goods and services. If the user does not provide their data or the Seller is unable to obtain them, the Seller may refuse to sign an agreement or can withdraw from an agreement.