This Privacy Policy provides information on the processing of personal data of data subjects by Colombe, registered office: Čremchová 10848/2A, 831 01 Bratislava – mestská časť Nové Mesto , Company ID: 50239112 , registered in Okresný úrad Bratislava, file no. 110-246704 (hereinafter the “Controller”), on the website ADD and on the Controller’s social media profiles (hereinafter the “Website”). We process all personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “GDPR”), Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendments to Certain Acts (the “Act”), and other relevant data protection regulations.
The purpose of this Policy is to explain why and how we process your personal data and to inform you of your rights and obligations in relation to such processing. This Policy also provides further relevant information and constitutes the Controller’s information notice under Articles 13 and 14 GDPR for processing on the Website. Conditions for any processing outside the Website are governed by the Controller’s general privacy policy and related internal data protection rules.
Your personal data are processed by Colombe, registered office: Čremchová 10848/2A, 831 01 Bratislava – mestská časť Nové Mesto , Company ID: 50239112 , registered in Okresný úrad Bratislava, file no. 110-246704.
E-mail: 4myhoodies@gmail.com
We process your personal data solely for specified purposes, by specified means and only for the period strictly necessary for those purposes. We implement appropriate technical and organizational measures to prevent unauthorized access, transmission, loss, destruction, or any other unlawful processing. All persons authorized to process your personal data are bound by confidentiality.
The Controller processes your personal data in line with the principle of data minimization—only to the extent necessary to fulfil contractual and legal obligations, to pursue legitimate interests, or based on your consent. We do not request data that are not necessary for the stated purpose.
We may process the following common personal data: first name, surname, mobile phone number, e-mail address, contact address, online identifiers (e.g., IP address, activity on the Website), and any other personal data you provide to us.
Performance of a contract or pre-contractual measures – Article 6(1)(b) GDPR.
We process your data when receiving and handling orders for services or goods—e.g., when you contact us via the Website contact form, social media message, e-mail, or by phone. The retention period is until all legal and other claims arising from the contractual relationship are settled, at least 3 years from its termination.
Consent – Article 6(1)(a) GDPR.
We process your data when you contact us with a request via the Website contact form or social media message. Retention: 3 months from receipt of the request or until it is handled, whichever occurs first.
Your consent is also required for measuring Website traffic and for targeted advertising performed via analytics and marketing cookies. Retention: until consent is withdrawn, but for no longer than 2 years.
Compliance with legal obligations – Article 6(1)(c) GDPR.
We process your data where necessary to comply with legal obligations—for example, when you submit a request to exercise your data subject rights. Retention: until the request is resolved.
The Controller may be obliged to provide your personal data to public authorities or other recipients legally entitled to process such data (e.g., courts or law enforcement authorities).
Other recipients may include social network operators if you contact us via social media (e.g., Facebook Inc.) and Google LLC as the provider of Google Analytics used to measure traffic on the Controller’s Website.
To ensure proper operations, the Controller has concluded data processing agreements with processors. Processors are selected to ensure your data remain secure and that they meet GDPR and Act requirements, including confidentiality obligations.
Processors may include companies or sole traders providing services to the Controller (e.g., web hosting, accounting), an online accounting and invoicing software provider, and a cloud storage provider.
In some cases, your personal data may be transferred to third countries:
• If you consent to the use of analytics cookies, data may be transferred to the USA to Google LLC (Google Analytics).
• If you contact us via social media, data may be transferred to the USA to Facebook Inc., the operator of Facebook.
All such transfers are safeguarded by Standard Contractual Clauses as part of the applicable service terms and our data processing agreements with the relevant providers.
We prioritize the security of your personal data. We have adopted necessary technical and organizational measures and continuously improve our safeguards in line with technological development (e.g., antivirus, firewalls).
If our systems were compromised and there were any risk of data leakage or harm to your rights, we will notify you within 72 hours of the measures taken and notify the Slovak supervisory authority (Úrad na ochranu osobných údajov) within the same period.
You have the following rights under the GDPR. You can exercise them by contacting: 4myhoodies@gmail.com.
If you are dissatisfied with how we process your personal data, please contact us at 4myhoodies@gmail.com. You also have the right to lodge a complaint with the Slovak supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava 27; website: dataprotection.gov.sk; tel.: +421 2 3231 3214; e-mail: statny.dozor@pdp.gov.sk.
We do not use profiling, nor do we carry out any automated individual decision-making that would evaluate your personal aspects.
When providing services to our clients, we may process personal data of data subjects on behalf of those clients. In such cases, we act as a processor within the meaning of Article 4(8) GDPR and process personal data strictly according to our clients’ documented instructions and applicable law.
We conclude data processing agreements with our clients, specifying the conditions for processing, security obligations, and appropriate safeguards for the processed personal data.
The purposes, legal bases, scope, and recipients of processing carried out by us as a processor are determined by the client. We do not perform any processing operations beyond those agreed with the client and required by law.
These updated Privacy Policy terms are valid and effective from 16 June 2021. As updates may be required in the future, the Controller reserves the right to amend and update this Policy at any time. You will be duly informed of any changes.