Personal data protection

We pay great attention to the privacy of visitors and customers in our online shop and we are aware that the personal data you entrust to us is sensitive information. We therefore undertake to protect it carefully against misuse, disclosure, unauthorised access and not to disclose it to third parties under any circumstances, in accordance with the Personal Data Protection Act (ZVOP-1) and the GDPR (EU 2016/679).

All data will be treated confidentially and will only be used for the purposes for which they were provided. We will only entrust the delivery service (e.g. Post of Slovenia, DPD, etc.) with the information necessary for the delivery of the ordered products (recipient’s details and delivery address).

Collection of personal data

When you visit our website, we store certain information about your device, your interaction with our website, and the information necessary to complete your purchase. Furthermore, we may collect information that we need to contact you for customer support.

Information about your device:

  • Examples of information we collect: your browser version, IP address, time zone, cookie information, which pages you open, how you interact with our website.
  • Purpose of collection: to load the website correctly, to perform analytics, and for website optimisation.
  • Source of collection: this information is automatically collected when you access our website using cookies, files, tags and pixels.

Your data:

  • name and surname
  • delivery address
  • contact number
  • email address
  • encrypted password
  • other data that the user voluntarily enters in the forms in the online shop (e.g. entering any notes when placing an order, entering a message when submitting a contact form)

These data are only needed to process your order or in case we need to contact you in connection with your order.

We are not responsible for the correctness, completeness and topicality of the data entered by the user. It is the user’s responsibility to protect the security of their personal data by ensuring the security of their username and password.

The user has the right to access and correction of their personal data. All the data we hold about you is accessible on your profile, where you can also correct them.

Sharing your data

We only share your data with companies that are necessary for the processing of your order, such as the delivery service and the website provider.

Our website is part of the WordPress platform, which also adheres to all the policies mentioned on this website.

Advertising

Your data may occasionally be used for advertising or for website analytics.

For example:

  • Facebook: we use the Facebook pixel, which uses some of the data collected via cookies.
  • Google Analytics: we use it to analyse the website.

You can always opt out of advertising by contacting us at info@plant-cosmetics.com.

Once saved, we will keep your data until you express your wish to have them deleted.

Right of access to data

You have the right to obtain confirmation from the data controller as to whether your personal data are being processed and, where this is the case, you have the right to obtain access to your personal data and to the following information in relation to the processing of your personal data: the purposes of the processing, the types of personal data, the users or categories of users to whom your personal data have been or will be disclosed, in particular users in third countries or international organisations; where possible, the envisaged period of retention of the personal data or, if this is not possible, the criteria used to determine this period; the existence of a right to request the data controller to rectify or erase the personal data or to restrict the processing of the personal data of the data subject or the existence of a right to object to such processing; the right to lodge a complaint with a supervisory authority; where the personal data are not collected from the user, any available information concerning their source; the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the user. Upon your request, you will be provided with a free copy of your personal data being processed. For additional copies of the data you may request, the data controller will charge you a reasonable fee, taking into account administrative costs.

Right to rectification

You have the right to request the data controller to rectify any inaccurate personal data without undue delay. You have the right to have incomplete personal data completed, including by submitting a supplementary declaration, taking into account the purposes of the processing.

Right to erasure (‘the right to be forgotten’)

You have the right to request the data controller to erase your personal data without undue delay, and the data controller must erase your personal data without undue delay in the following cases: where the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; where you withdraw the consent on which the processing of your personal data is based and there is no other legal basis for the processing; where you object to the processing on the basis of the legitimate interest of the data controller and there are no overriding legitimate grounds for the processing; where you object to the processing for the purposes of direct marketing; where the personal data must be erased in order to comply with a legal obligation under EU or Slovenian law.

Right to restriction of processing

You have the right to request that the processing of your personal data be restricted where one of the following applies: where you contest the accuracy of the data for a period enabling the data controller to verify the accuracy of your personal data; where the processing is unlawful and you object to the erasure of your personal data and instead request the restriction of their use; where the data controller no longer needs the personal data for the purposes of the processing but you need them for the establishment, exercise or defence of legal claims; where you have lodged an objection to the processing, pending verification whether the data controller’s legitimate grounds override your grounds.

Right to data portability

You have the right to receive your personal data held by the data controller in a structured, commonly used and machine-readable format, and the right to have that data transmitted to another data controller without being prevented from doing so by the data controller to whom the personal data have been provided, where the processing is based on your consent or on a contract and the processing is carried out by automated means.

Right to object

You have the right to object at any time to the processing of your personal data on grounds relating to your particular situation, provided that the processing is based on legitimate interests pursued by the data controller or by a third party. The data controller shall cease processing your personal data unless it demonstrates compelling reasons for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. Where personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for the purposes of such marketing, including profiling to the extent that it is related to such direct marketing. If the direct marketing is based on consent, the right to object may be exercised by withdrawing the provided personal consent.

Exercising your rights

Your exercise of these rights is subject to certain exceptions to safeguard the public interest (e.g. the prevention or detection of crime), the interests of the data controller (e.g. ensuring the protection of confidentiality) or the rights and freedoms of others. Please also note that proof of your identity and full details of your request may be required before it is processed. If you exercise any of the above rights, a reply will be given without undue delay, but no later than within one month. In complex cases or where a large number of requests are received, this deadline may be extended by a further two months, of which you will be informed.

You can contact info@plant-cosmetics.com both to exercise your rights and if you have any questions or if you wish to communicate your wishes or comments on data protection to the data controller.
If you are not satisfied with the processing of your data or with the response to any exercise of your rights, you have the right to complain to the data protection authority, the Information Commissioner of the Republic of Slovenia (address: Dunajska 22, 1000 Ljubljana, email: gp.ip@ip-rs.si, telephone: 012309730, website: www.ip-rs.si).

Cookies

This website uses cookies to provide you with a better user experience and to monitor visitor statistics. When you visit the website, certain information (IP address, date, time, address of the page you are coming from) is stored on the server. This information is anonymous and is used solely to analyse website visits (in conjunction with Google Analytics). Visitors are informed about the use of cookies when they first visit the website, while some cookies require the visitor’s consent. The visitor can change their choice regarding the use of cookies at any time on this website.

The website does not provide cookies to external service providers and does not use them to display advertising messages.

About cookies

Cookies are small text files that a website uploads to your web browser when you visit it. Some cookies are essential for the website to function properly. Cookies do not contain any personal or other information that can be used to identify the user, so we recommend that you consent to their use.

Visitors can withdraw their consent to the use of individual cookies at any time by clicking the button below. Withdrawal of consent may result in the altered functioning of certain functionalities of the website or make it impossible to use certain services.

Managing cookies in your browser

Most web browsers automatically accept cookies, and cookies are automatically deleted by the browser when they expire. You can also manually delete all cookies or cookies for a particular website (domain) or disable the use of cookies in your browser altogether. Instructions on how to delete or disable cookies can be found in the help section of your web browser. If you disable the use of cookies completely, some functionalities of the website will not work properly.

Changes to the Privacy Policy

Pridržujemo si pravico, do spremembe politike zasebnosti zaradi spremembe pogojev poslovanja ali spremembe zakonodaje.

Contact

Please contact us at any time at +38670228866 or info@plant-cosmetics.com for any questions or complaints you might have or to request the deletion of your data.