INFORMATION ON PERSONAL DATA PROCESSING
In connection with the processing of personal data, we provide you with the following information pursuant to the Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
WHO IS THE CONTROLLER
The controller who has determined the purposes and means of processing your personal data is Veles-X, s.r.o., located at A.Stodolu 5264/31, 036 01 Martin, Company ID: 51 001 268, Tax ID: 2120 549 321, VAT ID: SK2120549321, registered in the Commercial Register of the District Court of Žilina, Section Sro, Insert 78512.5/L.
You can contact us by phone at +421 947 948 946 or by email at podpora@velesx.sk.
SCOPE OF PERSONAL DATA AND SECURITY
We minimize the scope of personal data we process to ensure the quality of services you expect from us, to fulfill legal obligations, and to protect our legitimate interests. We process personal data of our customers and potential customers who have given us their consent. We process the following categories of personal data:
· Basic data, such as your name, surname, residential address, and Company ID if you are a sole trader.
· Contact data, such as your email, phone number, or contact address.
· Registration data (name, password) and account settings if you registered before making a purchase.
· Information about the products and services you have purchased or are considering purchasing. This includes data from orders, invoices, payments, or shopping cart contents.
· Information about the use of our e-shop, your behavior during the visit, the pages you view, the links you click, and the way you navigate through pages. This includes information about your device (technical parameters, operating system, screen resolution, browser used), the IP address of your device, and the geographical location derived from it, as well as data obtained through cookies and similar technologies.
· Data about reading our newsletter. Whether the messages were delivered, the time the messages were opened, the content that interested you, the links clicked in the messages, and data obtained through cookies and similar technologies.
· Records of email and chat communication, phone call records, or other communication with you in electronic or written form.
· Transaction data, primarily information about your payments and payment methods.
· Technological data and logs recorded in information systems during your visits to our website or communication. These data include the static (permanent) or dynamic (temporarily assigned) IP address of your device, operating system data, browser used, and the time and duration of the visit or communication.
Your personal data is protected by effective security technologies and organizational measures. All data is encrypted, protected by next-generation firewalls, and regularly backed up. Only professionally trained employees and vetted suppliers have access to it.
More information about the technical and organizational security measures we have implemented as a digital service provider according to cybersecurity law, based on ISO/STN 27001 standards, will be provided upon request.
PURPOSES AND LEGAL BASES FOR PROCESSING
We process your personal data primarily to enable you to shop conveniently and to deliver the ordered goods. We process your personal data in accordance with the law, based on the following legal grounds:
Processing based on the consent of the data subject according to Article 6(1)(a) of the GDPR
· For sending newsletters, which you can subscribe to via our website. You can unsubscribe from the newsletter at any time.
· For displaying behavioral advertising based on your interests from previously visited pages. You can withdraw your consent given through cookies at any time. (More about cookies: cookies)
· For organizing consumer competitions, which you can voluntarily participate in if you meet the conditions of the specific competition.
Processing based on contract performance according to Article 6(1)(b) of the GDPR
· For ordering and delivering goods (preparation and execution of remote purchase contracts)
· For business communication, during the preparation and execution of business contracts, ordering goods, delivery, and providing related information.
· For registration on the e-shop, which precedes contract conclusion and allows you to make repeat purchases more conveniently, get an overview of your orders, and access and edit your data.
· For providing delivery data to couriers. The courier companies used by us provide services according to postal law, and subsequently process your data as a third party for the necessary period to deliver parcels.
Processing based on legal obligation according to Article 6(1)(c) of the GDPR
· For handling complaints, according to consumer protection law and distance selling law.
· For accounting and tax administration, according to accounting and tax laws.
· For network and information systems security, according to cybersecurity law and GDPR Article 32.
· For handling requests related to exercising data protection rights, according to the GDPR.
Processing based on legitimate interest according to Article 6(1)(f) of the GDPR
· For sending newsletters to customers, in connection with registration or purchase. You can unsubscribe from the newsletter at any time.
· For verifying customer satisfaction, in connection with the last purchase.
· For communication via social networks, in connection with your interaction with content published by us via our fan page, website, newsletter, blog, etc.
· For legal agenda management, related to proving, defending, and asserting legal claims.
· For monitoring stores with a camera system, intended to protect the property of the controller and customers, and to protect the health and life of persons present in the store premises.
CATEGORIES OF RECIPIENTS
Your personal data may be provided to the following categories of recipients during processing:
· Courier and shipping companies
o Slovak Parcel Service s.r.o., located at Senecká cesta 1, 900 28 Ivanka pri Dunaji, Company ID: 31 329 217
o Zásielkovňa s.r.o., located at Kopčianska 3954/39, 851 01 Bratislava, Company ID: 48 136 999
· Additionally, law firms, accounting firms, auditors and tax advisors, experts and court experts, collection companies and bailiffs, courts, and law enforcement agencies.
PERSONAL DATA RETENTION PERIOD
If we process your data based on consent, we will process it for the duration of your consent but no longer than 3 years. After this period, we will destroy it. This period may also be shorter, for example:
· For sending newsletters, 24 months from the last opening
· For displaying behavioral advertising depending on the type of advertising system, 6 months to 3 years
If we process your data based on contract performance, we will process it for the duration of the contract and 5 years after its termination.
If we process your data based on legal obligation, we will process it for the period specified by the relevant legislative regulation.
· For accounting, this period is 10 years
· For complaints, this period is 2 years from the complaint
· For cybersecurity, this period is 12 months
If we process your data based on legitimate interest pursued by the controller, we will process it for the period necessary to achieve the purpose of the processing.
· For camera systems, this period is 72 hours.
· For sending newsletters, 24 months from the last opening
· For proving, defending, and asserting legal claims, until the statute of limitations expires. (For civil disputes, this period is 3 years)
YOUR RIGHTS REGARDING PERSONAL DATA PROTECTION
We are ready to exercise your rights regarding the processing of your personal data.
· You have the right to access your personal data, as well as the right to know the purpose for which it is processed, who the recipients of your personal data are, and the retention period.
· You have the right to rectification if your personal data is incorrect or has changed, contact us, and we will correct it.
· You have the right to erasure of personal data if it is incorrect or unlawfully processed.
· If your personal data is processed based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
· You have the right to restriction of processing if you wish, we will process the data only for the most necessary legal reasons or not at all.
· You have the right to data portability, if you wish to transfer it to another controller, we will provide it in the appropriate format, unless other technical or legal obstacles prevent it.
You have the right to lodge a complaint with a supervisory authority, which is the Office for Personal Data Protection of the Slovak Republic, located at Hraničná 12, 820 07 Bratislava 27, Slovak Republic, Company ID: 36 064 220, tel.: +421 2 3231 3220, https://dataprotection.gov.sk/uoou/.
WHERE AND HOW YOU CAN EXERCISE YOUR RIGHTS
You can also exercise your rights by calling +421 947 948 949, writing to A.Stodolu 5264/31, 036 01 Martin, or by email at podpora@velesx.sk.
We will respond to your request free of charge within 30 days. In case of complexity or a large number of requests, we are entitled to extend this period by an additional 60 days. If this happens, we will inform you about it and the reasons.
However, if your request is manifestly unfounded or repetitive, we are entitled to charge a reasonable administrative fee to cover the costs of providing this service.