Protection of personal data

1. Administrator

Registered business name of company: Kozmetika Afrodita d.o.o.
Head office of company: Rogaška Slatina
Business address: Kidričeva 54, 3250 Rogaška Slatina


Questions concerning the confidentiality of your data, the method of collecting and processing data or your requests to exercise rights in relation to your data will be answered by the responsible officer at the administrator:


As the personal data administrator, Kozmetika Afrodita d.o.o. respects your right to privacy and strives for the highest level of protection for your personal data. For this reason in offering our services via our website we are bound to operate in accordance with the law and regulations that define personal data protection, particularly in accordance with the currently valid Personal Data Protection Act, the Electronic Communications Act and the EU General Data Protection Regulation.

We provide this Personal Data Protection Statement for the purpose of informing you for which purpose your personal data will be obtained and how these data will be processed, and what rights you have regarding the data we keep about you, as well as the way you can exercise your rights.

The administrator undertakes to ensure that collected personal data which you submit via the website will be used in accordance with this Personal Data Protection Statement, that your personal data will not be sold, lent or in any other way communicated to third persons, except in legally provided cases.

2. Use, scope and purpose of storing and processing

We store and process personal data for the purpose of maintaining contact with customers through news, market communication via e-mail, promotional sales and profiling customers with the aim of offering content and products suited to the customer by e-mail and on our website.
For the purpose of notifying via e-mail we keep: e-mail address, name and surname. We collect personal data with the consent of the individual. We keep the consent together with the pertaining content and the content of the form with which it was obtained. Personal data are used by us in the following departments: sales department, marketing, customer support, accounting.

Visits to the administrator’s website:

On each visit to the administrator’s website, the web server automatically records a daily server file (e.g. IP number – the number that identifies the individual computer or other device on the web; the browser version, time of visit and similar). We process these data for the purpose of keeping visit statistics for our website. On our website you can fill in an online form submitting your enquiry about the provision of services. The administrator does not process data collected in this way separately and does not link them to other data.

3. Method and period of storage

We guarantee that your data will be stored only for as much time as is necessary to fulfil the purpose for which the individual data were collected and then used.

Personal data of individuals will be stored until the deletion of the entire database:
- if the above-described purposes for which personal data are stored and processed cease in our company, we will immediately and permanently delete the databases whose purpose has ended or

  • - up until the withdrawal of consent for storage and processing of the individual’s data.
    After the individual’s withdrawal of consent their personal data will be immediately and permanently deleted.

Personal data are kept in computerised and printed form. Our computer systems are protected with technical and organisational means that prevent unintended or unlawful destruction, loss, alteration and unauthorised disclosure of or access to your personal data. Personal data in printed form are protected in a secure metal cabinet and in cabinets that can only be accessed by the person authorised for such data. The company’s business premises are entirely secured with an alarm system in cooperation with an external partner.

As our website contains certain links to other sites which are in no way affiliated with the administrator, we assume no responsibility for the protection of data on those sites.

4. Users

All data collected on a legal basis will be used in accordance with the purpose for which they were collected, and will not be communicated to third persons without your consent.

Within the framework of legal competence your personal data may be disclosed to the following data users:

  • providers of postal services, providers of forwarding services;
  • providers of information technology services in the context of servicing and maintaining software;
  • the administrator of the website.

The administrator undertakes not to communicate or forward your personal data to any third country or international organisation.

5. Rights of the individual

If you no longer wish to receive notices of new features by e-mail, you can unsubscribe by using the link for automatically unsubscribing in any e-mail notice from us, or send us an e-mail to the address:

Each individual may at any time demand of the administrator in respect of their data: access, correction, termination of processing and storage or withdrawal of consent for processing and storage.

An individual to whom personal data relates may at any time require the administrator to:

  • confirm whether the data relating to them is being processed or not,
  • enable access to personal data (i.e. access and transcription or copying),
  • provide information relating to the processing of such data (e.g. the purpose of processing, type of personal data, users to which personal data were or will be communicated, the envisaged period of data storage, the technical and organisational measures for protecting data and so forth),
  • enable the correction of inaccurate personal data relating to them and enable them to supplement incomplete personal data,
  • facilitate the right to deletion of personal data (the right to be forgotten),
  • facilitate the right to restriction of processing,
  • facilitate the right to object to processing, if data processing is based on the lawful interest of the administrator, including the creation of profiles,
  • facilitate the right to transferability of data and communicate to them data in a generally used and machine readable format or to communicate them directly to another administrator,
  • facilitate the right to withdraw consent wherever personal data are processed on the basis of consent, where withdrawal of consent does not impinge on the lawfulness of data processing that was carried out up until the withdrawal,
  • provide additional information on their right to complain to the competent supervisory authority.

Equally the administrator will provide to the individual at their request, in accordance with the valid legislation, other information in connection with their personal data that is being processed.

At the request of an individual to whom personal data relate, the administrator will respond without unnecessary delay, but by no later than the prescribed deadlines, by e-mail or in writing by ordinary post, if so requested by an individual. 

6. Changes

We reserve the right where necessary to adapt the Personal Data Protection Statement occasionally to actual circumstances and legislation in the area of personal data protection. For this reason we ask that before any submission of personal data you check the current version in order to be informed about possible amendments.

Rogaška Slatina, 

May 2018