This privacy policy describes how SATEJ d.o.o. (hereinafter referred to as the controller) collects, uses, and protects the personal data of users of the website www.tekmec.si, in accordance with Regulation (EU) 2016/679 (GDPR), ZVOP-2, and applicable Slovenian legislation.
Data controller
SATEJ d.o.o.
Pekel 26, Pekel
2211 Pesnica pri Mariboru
Slovenia
Email: info@satej.si
The controller does not have a designated data protection officer (DPO), as there is no legal obligation to do so.
What personal data we process
The controller may process the following types of personal data:
- first name and last name,
- delivery and billing address,
- email address,
- phone number,
- data on orders and purchased products,
- data necessary for payment processing (the controller does not store payment card information),
- IP address and basic technical data about website visits.
Purposes and legal bases for processing
Personal data is processed for the following purposes and on the following legal bases:
- execution of orders and contractual relationship (order processing, delivery, payments, notification of order status) – contract (6(1)(b) GDPR),
- fulfilling legal obligations (issuing invoices, tax and accounting records) – legal obligation (6(1)(c) GDPR),
- communication with customers and handling of requests – legitimate interest (6(1)(f) GDPR),
- ensuring the security and technical operation of the website – legitimate interest (6(1)(f) GDPR),
- sending notifications or marketing content, where applicable – user consent (6(1)(a) GDPR).
The user can withdraw consent at any time.
Disclosure of personal data
The controller may disclose personal data to contractual processors when necessary for the performance of services, in particular:
- payment service providers (e.g., Stripe),
- accounting and IT providers.
The controller has appropriate personal data processing agreements in place with all processors.
Personal data is not sold and is not disclosed to unauthorized third parties.
Transfer of data to third countries
If individual service providers process data outside the European Union, the controller ensures that appropriate safeguards are in place in accordance with the GDPR (e.g., standard contractual clauses).
Retention of personal data
Personal data is stored only for as long as is necessary to achieve the purpose of processing:
- data on orders and invoices are kept in accordance with tax legislation,
- communication data until the matter is resolved,
- data processed on the basis of consent, until the withdrawal of consent.
User rights
In accordance with the GDPR, the user has the right to:
- access to personal data,
- correction of inaccurate data,
- deletion of data, where permissible,
- restriction of processing,
- data portability,
- objection to processing,
- withdrawal of consent at any time.
Rights can be exercised by sending a written request to info@satej.si.
Protection of personal data
The controller implements appropriate technical and organizational measures to protect personal data from loss, misuse, or unauthorized access.
Cookies
The website uses cookies. Details are described in the Cookie Policy, published on the website.
Changes to the privacy policy
The controller reserves the right to change this privacy policy. Changes take effect on the date of publication.
Complaints and supervisory authority
The user has the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia if they believe that their personal data is being processed in violation of the law.