PRODOM spol. s r.o., with its registered office at Vajnorská 2/E, 900 28 Ivanka pri Dunaji, Slovak Republic, Company ID (IČO): 30 777 011, registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, File No.: 2129/B,
as the Controller, provides this Data Subject Information Notice in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “Regulation”) and pursuant to Section 19 of Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendment and Supplementing of Certain Acts,
under the title:

 

PRIVACY POLICY

Purpose of personal data processing in relation to handling your order/contract registration:
Within the operations of the online store, personal data are processed for the purpose of fulfilling your order – i.e. for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract, as well as for the performance of rights and obligations arising from the contractual relationship between the data subject and the Controller.

Categories of data subjects:
Natural persons – contractual parties

Scope of processed personal data:
First name, last name, permanent/temporary residence address, telephone number, email address, bank account number of the natural person, bank name, data related to the subject of the contract, which may include processing of personal data such as title, photographs, date of birth, signature.

Legal basis for personal data processing:
Section 13(1)(b) of Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendment and Supplementing of Certain Acts; Act No. 40/1964 Coll. Civil Code, as amended; Act No. 108/2024 Coll. on Consumer Protection and on Amendment and Supplementing of Certain Acts; and other related generally binding legal regulations.

Categories of recipients:
Entities authorized by special legislation to make decisions regarding the rights and obligations of natural persons: courts, law enforcement authorities, and processors such as:
Packeta Slovakia s. r. o., with registered office at Sliačska 1E, 831 02 Bratislava – Nové Mesto, Company ID: 48 136 999.

Transfers of personal data to third countries:
No transfers to third countries are carried out.

Retention periods for personal data:
Contracts – 10 years

Automated decision-making including profiling:
Does not take place.

Note on data minimization:
All personal data provided by you represent a necessary legal requirement for fulfilling the purpose of processing.

 

Purpose of Personal Data Processing in Connection with User Profiles in the Application:

As part of its activities, the Controller processes personal data in connection with the creation and use of user profiles within the Controller’s application, which are provided by the natural person – user during registration, account creation, or further use of the application.

Categories of data subjects:
Natural persons – users

Scope of processed personal data:
First name, last name, title, nickname, profile photo, permanent residence address, territorial area of operation, date of birth, telephone number, email address, signature, location data, profession, hobbies, uploaded photos, files and data, embedded links, data from social media, IP address.

Legal basis for processing personal data:
Data subject’s consent; Section 13(1)(b) of Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendments and Supplements to Certain Acts.

Categories of recipients:
Entities authorized by special legislation to make decisions regarding the rights and obligations of natural persons: courts, law enforcement authorities; processors: Apple Inc., Google LLC.

Transfers of personal data to third countries:
No data transfers to third countries are carried out.

Retention period:
Application profile – 10 years

Automated decision-making including profiling:
Not performed.

The data subject has the right to withdraw consent to the processing of their personal data at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. The data subject must be informed of this before granting consent. Consent can be withdrawn using the same method by which it was given.

 

Purpose of Personal Data Processing in the Accounting and Tax Document Records:

As part of its activities, the Controller processes personal data for the purpose of processing accounting documents and related administrative tasks.

Categories of data subjects:
Natural persons – contractual parties, employees

Scope of processed personal data:
First name, last name, title, permanent residence address, temporary residence address, telephone number, email address, date of birth, type and number of identification document, signature, bank account number of the natural person.

Legal basis for processing personal data:
Act No. 431/2002 Coll. on Accounting, as amended; Act No. 222/2004 Coll. on Value Added Tax, as amended; Act No. 40/1964 Coll. Civil Code, as amended; Act No. 152/1994 Coll. on the Social Fund, as amended; Act No. 311/2001 Coll. Labour Code, as amended.

Categories of recipients:
Social Insurance Agency, health insurance companies, tax authorities, and entities authorized by special legislation to decide on the rights and obligations of natural persons: courts, law enforcement authorities; processors: external accountant managing accounting records.

Transfers of personal data to third countries:
No data transfers to third countries are carried out.

Retention period:
Accounting documents – 10 years

Automated decision-making including profiling:
Not performed.

In accordance with the principle of data minimization, all personal data you provide represent a necessary legal requirement to fulfill the purpose of processing.

 

Purpose of Personal Data Processing in Incoming and Outgoing Mail Records and Registry Management:

As part of its activities, the Controller processes personal data during the registration of incoming and outgoing mail and operations related to registry management.

Categories of data subjects:
Natural persons – recipients, employees

Scope of processed personal data:
First name, last name, title, address, organization name, job position, email address, subject and content of correspondence.

Legal basis for processing personal data:
Act No. 395/2002 Coll. on Archives and Registries and on Amendments to Certain Acts, as amended.

Categories of recipients:
Entities authorized by special legislation to make decisions regarding the rights and obligations of natural persons: courts, law enforcement authorities.

Transfers of personal data to third countries:
No data transfers to third countries are carried out.

Retention period:
Regular correspondence – 3 years

Automated decision-making including profiling:
Not performed.

 

Purpose of Personal Data Processing in the Complaints Register:

As part of its operations, the Controller processes personal data for the purpose of recording individuals in connection with the submission of complaints.

Categories of data subjects:
Natural persons – contractual parties

Scope of processed personal data:
First name, last name, title, residence, telephone number, email address, and nature of the complaint

Legal basis for processing personal data:
Act No. 40/1964 Coll. Civil Code, as amended; Act No. 108/2024 Coll. on Consumer Protection and on Amendments and Supplements to Certain Acts; and other relevant generally binding legal regulations

Categories of recipients:
Slovak Trade Inspection (SOI) – pursuant to Act No. 128/2002 Coll. on State Supervision of the Internal Market in Consumer Protection Matters and on Amendments to Certain Acts; and entities authorized by special legislation to decide on the rights and obligations of natural persons: courts, law enforcement authorities

Transfers of personal data to third countries:
No data transfers to third countries are carried out.

Retention period:
Complaints – 10 years

Automated decision-making including profiling:
Not performed.

In accordance with the principle of data minimization, all personal data you provide represent a necessary legal requirement to fulfill the purpose of processing.

 

Purpose of Personal Data Processing for Marketing:

As part of its operations, the Controller processes personal data to register individuals for the purpose of sending marketing offers, newsletters, product information, and updates.

Categories of data subjects:
Natural persons

Scope of processed personal data:
Email address

Legal basis for processing personal data:
Data subject’s consent

Transfers of personal data to third countries:
No data transfers to third countries are carried out.

Retention period:
Marketing – 13 months

Automated decision-making including profiling:
Not performed.

The data subject has the right to withdraw their consent to the processing of personal data at any time. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. The data subject must be informed of this prior to providing consent. Consent may be withdrawn in the same manner as it was given.

 

Purpose of Personal Data Processing – Contact Form:

As part of its operations, the Controller processes personal data in the client register for the purpose of responding to submitted inquiries.

Categories of data subjects:
Natural persons – clients

Scope of processed personal data:
Title, first name and surname, telephone number, email address, message content

Legal basis for processing personal data:
Data subject’s consent

Categories of recipients:
Entities authorized by special legislation to decide on the rights and obligations of natural persons: courts, law enforcement authorities

Transfers of personal data to third countries:
No data transfers to third countries are carried out.

Retention period:
Contact form – up to 6 months (in the event of legal obligations or claims of the Controller in accordance with applicable legislation)

Automated decision-making including profiling:
Not performed.

The data subject has the right to withdraw their consent to the processing of personal data at any time. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. The data subject must be informed of this prior to providing consent. Consent may be withdrawn in the same manner as it was given.

 

Rights of Data Subjects

Data subjects whose personal data are processed for specifically defined purposes may exercise the following rights:

These rights are further specified in Articles 15 to 21 of the GDPR. Data subjects exercise these rights in accordance with the GDPR and other applicable legal regulations. Rights may be exercised through a written request or via electronic means. If a data subject requests that the information be provided orally, such information may be delivered orally provided that the identity of the data subject has been verified.

PRODOM spol. s r.o. has adopted all appropriate personnel, organizational, and technical measures to ensure maximum protection of your personal data, with the aim of minimizing the risk of misuse.
In accordance with Article 34 of the GDPR, we hereby inform you that, should a personal data breach occur that is likely to result in a high risk to your rights and freedoms, we will notify you of this breach without undue delay.

Legal regulations and the ways in which your personal data are processed may change. If we decide to update these principles, we will publish such changes on our website and inform you accordingly. In the event of significant changes or if required by law, we will notify you in advance.
We ask that you review these principles carefully and check them regularly when communicating with us or using our website.

If you have any questions regarding the processing of your personal data, including exercising the rights mentioned above, you can contact us at: info@fulpio.com
If you are not satisfied with our response or believe that we are processing your personal data unfairly or unlawfully, you may lodge a complaint with the supervisory authority:

Office for Personal Data Protection of the Slovak Republic
https://dataprotection.gov.sk
Hraničná 12, 820 07 Bratislava 27
Tel: +421 /2/ 3231 3214
Email: statny.dozor@pdp.gov.sk

 

Cookies

What are cookies?
Cookies are text files stored on the visitor’s end device (computer or mobile device) during their visit to a website. They are stored locally and allow for the analysis of how visitors use our website. Cookies must not contain personal data and cannot identify you on third-party websites, including analytics providers. Consent is required for their use.

What cookies do we use, based on different criteria?
We only use necessary cookies that enable the proper functioning of our website. These may include:

Such processing takes place in accordance with Act No. 452/2021 Coll. on Electronic Communications, where § 109(8) requires demonstrable consent to obtain information from the visitor’s end device.

Consent under Article 6(1)(a) of the GDPR is required for cookies:

Without valid user consent, only technical cookies (e.g., for chat windows or basic visitor tracking without personal identification) may be used. Such cookies are necessary for the website to function and do not require user consent.
We do not recommend relying on legitimate interest as a legal basis for the processing of other types of cookies.

If your website does not process any personal data via cookies, a cookie banner is not required.

 

General Cookie Usage Rules

Step 1:
The operator must examine the website to identify:

Step 2:
The website must implement a cookie banner that:

If a third party (e.g., freelancer or external company) manages your website and processes data, a data processing agreement must be in place.

 

Step 3 – GDPR Information Obligation:
You must inform users about:

Final Notes on Enforcement and Fines

  1. The Regulatory Authority for Electronic Communications and Postal Services may impose a fine ranging from €200 up to 10% of annual turnover, in accordance with § 124(1) of Act No. 452/2021 Coll., for violations of § 109.
  2. The Office for Personal Data Protection may impose fines of up to €20,000,000 or 4% of total global annual turnover for non-compliance with obligations related to cookie consent and transparency.

 

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.