Privacy Policy
1. Initial Provisions
EXOR ETI d.o.o., Brnčičeva ulica 51, 1231 Ljubljana – Črnuče, Slovenia, registration number: 1941224000 ("EXOR ETI"), respects the right to privacy and aims for the highest level of personal data protection. Therefore, when providing our services, we undertake to act in accordance with the laws and regulations on protection of personal data, in particular the applicable Slovenian Personal Data Protection Act, Slovenian Electronic Communications Act and EU General Data Protection Regulation (GDPR).
EXOR ETI undertakes to use the personal data collected in accordance with this Privacy Policy and not to sell, lend or otherwise disclose personal data to third parties, except in cases provided for by law and in cases when personal data is disclosed to our contractual processors, as specified in the applicable Privacy Policy.
2. Purpose of the Document; Privacy Policy
Should you provide us with any personal data through the website, via email or otherwise, we will respect your privacy in accordance with GDPR. Our data protection policy is as follows:
• we inform users about exactly how and for what purpose the data they enter in different forms will be used;
• this data is never accessible to third parties;
• we never rent, sell or allow any third party to use our users' personal data, unless stated otherwise in this Privacy Policy;
• we regularly check and update our databases to ensure that they contain as few errors as possible.
3. Data Controller
Data Controller is EXOR ETI, with the details as specified in section 1 above.
4. Purpose of Data Processing and Types of Personal Data
Any personal data provided to us by our customers will be treated confidentially and will be used solely for the purposes for which it was provided. If a need arises to further process the data for another purpose, we will ask our customers to give their consent prior to processing.
5. Visiting the Website
Each time you visit the exor-eti.si website, a web server log file is automatically stored on the web server (e.g. IP address - a number that identifies a particular computer or other device online; browser version, time of visit, etc.). We process this data in order to keep statistics on website visits.
EXOR ETI d.o.o. does not process the data collected in this way separately and does not link it to other data.
6. Subscribing to our Newsletter
On our exor-eti.si website, customers can subscribe to our newsletter, which contains announcements, invitations to events and offers of services. For this purpose, EXOR ETI can send you emails about new or upgraded services, upcoming events and trainings and other relevant news directly related to EXOR ETI's activities. We inform our customers about news periodically and no more than twice a month. The legal basis for the processing of personal data for customer information purposes is the consent given when you provide us with your personal data or the contract concluded with you.
To send our newsletters, we use the MailChimp platform, sharing with it personal data such as first name, last name, email address and company or just some of these data. MailChimp is our contractual processor in this respect, and we have concluded an adequate contract with them and have verified that they implement appropriate safeguards to protect your personal data.
Customers can unsubscribe from the newsletter at any time. Additional information on your rights in relation to direct marketing is available in Section 9 – Customer Rights.
7. Data Users
All data will be used in accordance with the purpose for which it was collected and will not be disclosed to third parties without the customer's consent, unless specified otherwise in this Privacy Policy or when we are required to do so by law or by a competent authority.
Within the scope of the legal powers, the customer's personal data is disclosed to the following data users:
• IT service providers for software servicing and maintenance;
• the provider of the platform for mass messaging.
EXOR ETI d.o.o. undertakes not to disclose or transfer our customers' personal data to third countries or international organisations, except if this is necessary in order for us to provide our services. In light of the above, we will ensure that in countries outside the European Economic Area whose laws may not ensure the same level of personal data protection, the data is only disclosed to trustworthy third parties. Where necessary, we will ensure that all appropriate safeguards are in place to meet the requirements for international transfers of personal data under applicable privacy laws. For transfers of personal data outside the European Economic Area, we will use Commission-approved mechanisms as safeguards, such as Privacy Shield certification and standard contractual clauses, such as the "(EU) controller to controller (outside the EU/EEA)" Decision 2004/915/EC (see Article 46 of the GDPR).
As pointed out in section 3, among others, we disclose data also to our processor MailChimp located in the United states of America, whose privacy policy can be found at this link. The company is certified under the Privacy Shield, which is subject to specific rules and requirements regarding the handling of personal data.
8. Unsubscribing
If customers no longer wish to receive email newsletter notifications, they may unsubscribe by using the automatic unsubscribe link provided in each newsletter, or by sending an email with the subject "UNSUBSCRIBE" to the email address: odjava@exor-eti.si.
Unsubscribing from the newsletter shall be deemed a withdrawal of your consent, which shall apply prospectively and shall not affect the lawfulness of the processing of personal data already carried out.
9. Data Retention Period
We retain customer data for as long as the account is active or as long as necessary to provide services to the customer. We may continue to retain data even after the customer stops using our services or until the customer unsubscribes. We retain the data and, if necessary, use the data to comply with our legal obligations or to settle any disputes. Therefore, when we retain the data for the performance of the contract concluded with you, we may retain it for the entire duration of any relevant limitation periods.
10. Data Protection Method
EXOR ETI undertakes to protect personal data. We will take all necessary steps to protect personal data from any breaches and misuse. We store personal data in digital form. Our computer system is protected by technical and organisational measures that prevent accidental or unlawful destruction, loss, alteration and unauthorised disclosure of, or access to, personal data. After the need to keep the data has ceased, i.e. after the purpose for which the data were collected has been fulfilled, or if you have withdrawn your consent, your personal data will be irretrievably and permanently deleted within 15 days. Should you wish to obtain additional information about our safeguards, please contact us at info@exor-eti.si.
11. Rights of the Data Subject
We will take all the necessary measures to ensure that your data is treated securely and in accordance with this Privacy Policy. Customers have the right to access their personal data and the right to rectify or delete their data. Furthermore, customers have the right to restrict the use of their data and the right to transfer their personal data to a third party.
Data subjects may at any time request that EXOR ETI
• enables them the rectification of inaccurate personal data concerning them and the completion of incomplete personal data;
• enables them to exercise the right to erasure of their personal data ("right to be forgotten");
• enables them to exercise the right to restriction of the use of their personal data;
• enables them to exercise the right to object to the processing of their personal data;
• enables them to exercise the right to data portability and provides the data to them in a commonly used and machine-readable format, or forwards the data directly to another controller;
• enables them to exercise the right to withdraw consent when personal data are processed on the basis of consent, whereby the withdrawal of consent shall not affect the lawfulness of processing of data carried out prior to the withdrawal;
• provides additional information on the data subject's right to lodge a complaint with the competent supervisory authority.
Upon request, EXOR ETI will also provide the data subject with other information relating to his or her personal data processed by EXOR ETI, in accordance with applicable law.
EXOR ETI undertakes to respond to requests from data subjects without undue delay and at the latest within the legal time limits.
The data subject also has the right to lodge a complaint with the supervisory authority.
Supervisory authority contact details:
Republic of Slovenia
Information Commissioner
Dunajska cesta 22
1000 Ljubljana, Slovenia
Phone: 01 230 97 30
E-mail: gp.ip@ip-rs.si
The data subject may exercise this right in accordance with the procedure and in the manner prescribed by the GDPR.
12. Our Contact Details
You can exercise all of the aforementioned rights by contacting us at info@exor-eti.si or by calling +386 1 511 10 95.
13. Changes to the Privacy Policy
We reserve the right to periodically update this Privacy Policy, if necessary, in order to adapt it to the actual situation and applicable legislation on personal data protection.
The Privacy Policy was updated on 20 May 2020.
In Ljubljana, 20 May 2020