Cookie settings
We use cookies to measure and analyse traffic. You can find out more on the Privacy Policy page.
Basic
Necessary for the operation of the site. Always on.
Personalisation
Used to remember visitor preferences.
Marketing
Used for targeted advertising.
Analytical
Used to measure traffic and improve the site.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
By clicking on the "Allow" button, you agree to the use of cookies to measure and analyse traffic. You can find out more on the Privacy Policy page.

Privacy Policy

I.

Basic provisions

  1. The controller of personal data pursuant to Article 4 point 7 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR") is Beáta Bileková - Shantala Baby Spa, Eliášovce 59, Nový Život 930 38, ID No.: 52095851, registered at the District Office of Dunajská Streda, Trade Register No.: 210-37334(hereinafter referred to as "the Controller").
  2. Contact details of the administrator are: address: Eliášovce 59, Nový Život 930 38, E-mail: info@shantala.sk
  3. Personal data means any information about an identified or identifiable natural person; an identifiable natural person is a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, a network identifier or to one or more specific elements of the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.
  4. The controller has not appointed a data protection officer.

II.

Sources and categories of personal data processed

  1. The controller processes personal data that you have provided to the controller or personal data that the controller has obtained on the basis of completing your order:
  • name and surname
  • e-mail address
  • postal address
  • Phone

 2. The controller processes your identification, contact and contract data.

III.

Legal basis and purpose for processing personal data

  1. The legal basis for the processing of personal data is
  • performance of the contract between you and the controller pursuant to Article 6(1)(b) GDPR
  • compliance with the controller's legal obligation under Article 6(1)(c) GDPR
  • the controller's legitimate interest in providing direct marketing (in particular sending commercial offers and newsletters) pursuant to Article 6(1)(f) of the GDPR,
  • Your consent to processing for the purpose of providing direct marketing (in particular for sending commercial offers and newsletters) pursuant to Article 6(1)(a) GDPR in conjunction with Section 7(2) of Act No. 480/2004 Coll., on certain information society services in the event that goods or services have not been ordered.

   2. The purpose of the processing of personal data is

  • processing your order and fulfilling the rights and obligations arising from the contractual relationship between you and the controller; when ordering, personal data are required that are necessary for the successful execution of the order (name and address, contact, email), the provision of personal data is a necessary requirement for the conclusion and performance of the contract, without the provision of personal data, the contract cannot be concluded or fulfilled by the controller,
  • the fulfilment of legal obligations towards the State,
  • sending business communications and other marketing activities.

IV.

Data retention period

  1. The controller stores personal data
  • for as long as necessary to exercise the rights and obligations arising from the contractual relationship between you and the controller and to assert claims arising from that contractual relationship (for a period of 15 years from the termination of the contractual relationship).
  • until the withdrawal of consent to the processing of personal data for marketing purposes. After the expiry of the retention period, the data controller shall delete the personal data.

V.

Recipients of personal data (subcontractors of the controller)

  1. Recipients of personal data are persons who
  • are involved in the delivery of goods/services/payment under the contract,
  • provide e-shop and other services in connection with the operation of the e-shop,
  • provide marketing services.

   2. The controller intends to transfer personal data to a third country (non-EU country) or an international organisation. Recipients of personal data in third countries are cloud and marketing service providers.

VI.

Processors of personal data

  1. The processing of personal data is carried out by the controller, but personal data may also be processed by the following processors:
  • Mailchimp service provider,
  • Billing service provider Stripe
  • Website provider Webyst
  • Google Analytics Provider, Tag Management
  • Provider Meta
  • Alternatively, another provider of software services and processing applications not currently used by the controller.

VII.

Your rights

  1. Under the terms of the GDPR, you have
  • the right of access to your personal data under Article 15 of the GDPR,
  • the right to rectification of personal data pursuant to Article 16 GDPR or restriction of processing pursuant to Article 18 GDPR,
  • the right to erasure of personal data under Article 17 GDPR,
  • the right to object to processing under Article 21 GDPR,
  • the right to data portability under Article 20 of the GDPR; and
  • the right to withdraw consent to processing in writing or electronically to the address or e-mail of the controller referred to in Article III of these Terms and Conditions.

   2. You also have the right to lodge a complaint with the Data Protection Authority if you believe that your right to data protection has been violated or to apply to the court.

VIII.

Privacy Policy

  1. The controller declares that it has taken all necessary technical and organisational measures to secure personal data.
  2. The controller has taken technical measures to secure the data archives and personal data in paper form, in particular Passwords, Encryption, Anti-virus.
  3. The controller declares that only authorised persons have access to personal data.

IX.

Final provisions

  1. By submitting an order from the online order form, you confirm that you are aware of the privacy policy and that you accept it in its entirety.
  2. You agree to these terms and conditions by ticking the consent box via the online form. By checking the consent box, you acknowledge that you are aware of the Privacy Policy and that you accept it in its entirety.
  3. The Administrator is entitled to change these terms and conditions. It will publish the new version of the Privacy Policy on its website and will also send you a new version of these terms and conditions to the email address you have provided to the controller.

These terms and conditions come into force on 1.7.2022.