Personal data protection

Personal data controller and contact details

This policy applies to the processing (use) of any personal data by AGENCIJA RENEE d. o. o. (controller) or carried out on behalf of the controller.

Controller information can be found at this https://savana-spa.si/en/about-us/ address.

What personal data do we process?

  1. Basic contact information (name, surname, telephone number, e-mail address).
  2. Information on the use of the website www.savana-spa.si (clicks on links, time spent on the page) and response to our e-mails.
  3. Information we need to fulfil the contract and perform the service (selected services, price, selected or used products, date, payment information).

Legal basis for the personal data processing

We may process your personal data on the following legal bases:

  1. when necessary to meet our legal obligations (e.g. invoicing);
  2. when the processing of your personal data is necessary for the conclusion and fulfilment of the contract (on the performance of the service), which you have concluded with us or because you have requested an offer from us;
  3. when you have given your consent to the processing of your personal data for a particular purpose of processing, where you always have the right to revoke the given consent;
  4. when we have a legitimate interest in the processing of your personal data (e.g. when we send you an SMS or e-mail reminder).

Purposes of personal data processing

We may use your personal information for one and/or more of the following purposes:

  1. ordering;
  2. information support in the performance of the service;
  3. communicating with you regarding the provision of our services and responding to your inquiries;
  4. conclusion of the contract and fulfilment of obligations arising from the concluded contract;
  5. marketing communication (sending e-mails, SMS and other e-mails);
  6. marketing communication based on customised or individualised offers and messages, for the creation of user profiles or grouping, each of which may receive marketing material with different content. When creating profiles, we also monitor the individual’s activity (such as the time an individual spends on certain content, which content they are interested in and e-mail viewing) and the frequency and value of past orders;
  7. enforcing any legal claims and resolving disputes;
  8. statistical service sale analysis and the use of our online applications.

How long do we keep your personal data?

We retain basic personal data for as long as you have the status of registered user on the website www.savana-spa.si. Personal data that we process on the basis of your consent are stored permanently or until you revoke the consent. We keep the data necessary for the conclusion and fulfilment of the contract between us for another five years from the fulfilment of the contract (performance of services).

Voluntary providing of data and consequences of not providing the data

Providing us with your personal data is voluntary. You are not obliged to provide us with personal data, but if you do not provide it, you cannot receive and/or use certain services or enter into contracts with us.

Who has access to your personal data?

We do not pass on your personal data and do not provide access to them to third parties, except those who have a written contract with us, on the basis of which they perform certain tasks related to data processing and are obliged to comply with legislation on personal data processing and protection (contractual processors). Contractual processors to whom we provide personal data are:

  • marketing service providers;
  • e-mail service providers;
  • SMS providers;
  • business management software providers.

Contractual processors may only process personal data in accordance with our instructions and may not process personal data for their own purposes. They are obliged, together with their employees, to protect the confidentiality of your personal data.

What rights do you have with regard to personal data?

With regard to your personal data, you have the right to request from us at any time:

  1. confirmation of whether we are processing your personal data;
  2. access to personal data and the following information: purposes of processing; types of personal data; users or categories of users to whom personal data have been or will be disclosed, in particular users in third countries or international organisations; the envisaged retention period of the personal data or, if that is not possible, the criteria used to determine that period; the existence of automated decision-making, including profiling and the reasons for it, as well as the importance and intended consequences of such processing for you;
  3. a free copy of personal data in a form you specify (if the request is made by electronic means of communication and you do not request otherwise, a copy shall be provided in electronic form); we may charge a reasonable fee, taking into account the costs, for additional copies you request;
  4. correction of inaccurate personal data;
  5. limitation of processing when you dispute the accuracy of personal data, for a period that allows us to verify the accuracy of personal data; when the processing is illegal and you object to the deletion of personal data and instead request a restriction on their use; when we no longer need personal data for the purposes of processing, you need it to assert, enforce or defend legal claims;
  6. deletion of all personal data (right to be forgotten) if the preconditions of Article 17 of the General Data Protection Regulation are met, and in particular in the event that you revoke your consent to the processing of personal data;
  7. printout of personal data in a structured and machine-readable form;
  8. cessation of the use of personal data for direct marketing purposes, including profiling;
  9. that you are not subject to a decision based solely on automated processing, including profiling, provided that the preconditions set out in Article 22 of the General Data Protection Regulation are met.

Procedure for exercising rights

You can address your requests for the exercise of personal data rights in writing to any contact listed under the personal data controller.

We must respond to your request to exercise your rights with regard to personal data without undue delay and at the latest within one month of receiving it.