PRIVACY POLICY
NEBBIA, s. r. o., with its registered office at Dlhá 74/85, 010 09 Žilina, Company ID (IČO): 52469778, as the operator of the website https://nebbia.fitness/ (hereinafter the “controller”), has adopted appropriate technical and organisational measures to protect your personal data. Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “GDPR”), as well as Act No. 18/2018 Coll. on Personal Data Protection and on Amendments to Certain Acts, require the controller to be transparent when processing your personal data. In connection with its activities, the controller processes personal data for various purposes, about which it informs you in more detail below.
Contact details of the controller:
NEBBIA, s. r. o.
Dlhá 74/85, 010 09 Žilina
Company ID (IČO): 52469778
Contact email: [email protected]
The controller processes your personal data in the following information systems:
1. Registry Management
We process your personal data for the purpose of archiving the controller’s documents and keeping records of incoming and outgoing mail in paper and electronic form, including through the state web application www.slovensko.sk. We process the personal data you provide, namely title, first name, surname and permanent residence address, on the basis of a legal obligation pursuant to Article 6(1)(c) of the GDPR, arising from Act No. 395/2002 Coll. on Archives and Registries and on Amendments to Certain Acts and Act No. 305/2013 Coll. on the Electronic Form of Exercising the Powers of Public Authorities and on Amendments to Certain Acts.
We process the personal data you provide for the following periods:
- general correspondence – 2 years;
- registry management (records aids, disposal of documents, etc.) – 10 years;
- incoming and outgoing mail log – 2 years;
- correspondence data (part of the client file) – 10 years.
2. Accounting Documents
We process your personal data for the purpose of processing the accounting documents of data subjects when entering into and performing pre-contractual and contractual relationships. We process the personal data you provide to the following extent: the first name and surname or business name of the taxable person, the address of its registered office, place of business, establishment or residence, or the address of the place where it usually resides, and the tax identification number under which it supplied the goods or services; or the first name and surname or business name of the recipient of the goods or services, the address of its registered office, place of business, establishment or residence, or the address of the place where it usually resides, and the tax identification number under which the goods or services were supplied to it; and the bank account number of a natural person. The processing is carried out on the basis of a legal obligation pursuant to Article 6(1)(c) of the GDPR, arising from Act No. 431/2002 Coll. on Accounting, as amended, Act No. 222/2004 Coll. on Value Added Tax, Act No. 40/1964 Coll., the Civil Code, and Act No. 513/1991 Coll., the Commercial Code. Data subjects are persons who are obliged to pay for the supplied services/goods. The retention period for personal data necessary for accounting is 10 years.
For accounting purposes, the controller uses the services of an external accounting company, which acts as a processor.
| Processor: | Legal basis: |
|---|---|
| MONESTI, s.r.o. Priemyselná 8817, 010 01 Žilina Company ID (IČO): 36438961 | Pursuant to Article 28 of the GDPR |
3. Complaints
We process your personal data for the purpose of handling complaints. We process the personal data you provide to the following extent: buyer identification data (first name, surname, street and number, city, postal code, telephone, email), seller identification data (business name, street and number, city, postal code, telephone, email, Company ID, Tax ID), the buyer’s IBAN, the buyer’s signature, the name of the employee handling the complaint, and the order/invoice number. The processing is carried out on the basis of a legal obligation pursuant to Article 6(1)(c) of the GDPR, arising from Act No. 40/1964 Coll., the Civil Code, Act No. 22/2004 Coll. on Electronic Commerce, as amended, Act No. 250/2007 Coll. on Consumer Protection and on Amendments to Act of the Slovak National Council No. 372/1990 Coll. on Offences, as amended, and Act No. 108/2024 Coll. on Consumer Protection and on Amendments to Certain Acts. Data subjects are customers and the persons responsible for handling complaints at the controller. The controller processes personal data for the period necessary to fulfil the purpose (3 years). The controller must retain some personal data for up to 10 years for archiving for tax purposes in accordance with applicable legislation.
4. Registration
We process your personal data for the purpose of creating a user account. The data you provide, namely your email and password, are used to log in to the user account, to send a forgotten password, and to process orders more quickly. The processing is carried out on the basis of your consent pursuant to Article 6(1)(a) of the GDPR. Data subjects for this purpose are persons who create a user account on the controller’s website. The controller processes personal data for 5 years from the last activity on the controller’s website.
5. Marketing
We process your personal data for the purpose of sending marketing offers – newsletters.
You can subscribe to our newsletter by entering your email address on our website. In that case, we will process your personal data, namely your email address, on the basis of your consent pursuant to Article 6(1)(a) of the GDPR. You may withdraw your consent at any time via the link in the footer of the newsletter email. We process your personal data until you withdraw your consent, but for no longer than 5 years from the date it was given. If you withdraw your consent, the consent and related information are archived for 4 years from its withdrawal (pursuant to Act No. 452/2021 Coll. on Electronic Communications).
If you have previously been in a pre-contractual or contractual relationship with us, or you are already our existing client, we will contact you for the purpose of sending marketing offers – newsletters without your consent, on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR. Our legitimate interest is the promotion of our products and services, for which we use your personal data, specifically the name and email address you provided to us as our client when previously using our services. You may object to this processing at any time. We process your data for a maximum of 1 year from the end of the contractual relationship.
For the above purposes, we use the services of a processor, namely the marketing platform Brevo.
| Processor: | Legal basis: |
|---|---|
| Brevo Operator: Sendinblue SAS Registered office: France | Pursuant to Article 28 of the GDPR |
6. E-shop
We process personal data for the purpose of ordering goods or services, or for the purpose of concluding a purchase contract between the controller and the customer, which also involves the subsequent payment, delivery of the goods or services, handling of any complaints and similar processes. The processing is carried out for the performance of a contract pursuant to Article 6(1)(b) of the GDPR. When processing personal data for the purpose of concluding a purchase contract and related processes (such as payment, delivery of goods or services, handling of any complaints, etc.), the e-shop operator has obligations arising from the following legislation: Act No. 40/1964 Coll., the Civil Code, Act No. 513/1991 Coll., the Commercial Code, Act No. 222/2004 Coll. on Value Added Tax, Act No. 431/2002 Coll. on Accounting, and Act No. 250/2007 Coll. on Consumer Protection and on Amendments to Act of the Slovak National Council No. 372/1990 Coll. on Offences, as amended.
We process your personal data to the following extent: first name, surname, region, street, postal code, city, telephone, email address and payment information. Data subjects are the controller’s clients. We process your personal data for the period necessary to fulfil the purpose, but for no longer than 3 years from the last activity on the account (except for data that must be archived for tax purposes, for which the retention period is 10 years under legal obligations).
Documents to which the customer has access, such as invoices and order forms, are stored on the e-shop’s web server operated through Digital Ocean, LLC. Accounting is handled by the external accounting firm MONESTI, s.r.o.
| Processor: | Legal basis: |
|---|---|
| Digital Ocean, LLC Parent company: DigitalOcean Holdings, Inc. Registered office: USA | Pursuant to Article 28 of the GDPR |
| MONESTI, s.r.o. Priemyselná 8817, 010 01 Žilina Company ID (IČO): 36438961 | Pursuant to Article 28 of the GDPR |
7. Cookies
The controller uses the following categories of cookies on its website:
- strictly necessary cookies for the purpose of providing services related to operating the website in its essential mode;
- analytical cookies for the purpose of determining the number of visits and sources of traffic – measuring and improving website performance;
- marketing cookies for the purpose of displaying targeted advertising on websites, as well as evaluating the effectiveness of advertising and tracking the number of users who were interested in the advertising.
| Cookie type | Legal basis for processing | Type of data |
|---|---|---|
| strictly necessary | Legitimate interest pursuant to Article 6(1)(f) of the GDPR – our legitimate interest is the proper functioning of the website and its basic features | When accessing and using the website, personal data automatically transmitted by the browser to the controller’s server are collected. The following information is recorded without intervention and stored until it is automatically deleted: the IP address of the requesting computer, the date and time of access, the name and URL of the retrieved file, the website from which access is made, the browser used and, where applicable, the operating system of the computer, as well as the name of the internet access provider |
| analytical | Consent pursuant to Article 6(1)(a) of the GDPR* | Cookies stored on the end device |
| marketing | Consent pursuant to Article 6(1)(a) of the GDPR* | Cookies stored on the end device |
*Consent is always voluntary and unconditional; therefore, even if the data subject does not give it, they can still visit and use the websites, online services and products to the extent that cookies are not necessary for their functionality and accessibility. If the use of cookies is disabled or restricted, this may affect the functionality and accessibility of the controller’s websites and services, and all or some of the services may not be fully functional or accessible.
Strictly necessary cookies are temporary and are automatically deleted when you close your web browser. Other types of cookies are classified as persistent and remain on your device until they expire, but for no longer than 13 months, or until you delete them yourself. As a website visitor, you can delete cookies at any time, regardless of whether they are persistent or temporary.
The controller uses third-party services on its websites, such as Google Analytics or Meta marketing tools. To use these services, the controller loads third-party code which may require cookies to be stored for full functionality. As a result, third-party cookies are accepted. If you accept the use of third-party cookies, your data may be transferred to countries outside the EEA (e.g. USA, China).
Notice:
pursuant to Article 49(1)(a) of the Regulation, when transferring personal data to third parties that are unlikely to provide the level of personal data protection customary in EEA countries:
Giving consent to the provision or disclosure of personal data through social networks and other means of communication whose operators are based outside the EEA (countries without an adequacy decision and without appropriate safeguards – “countries not considered safe in terms of the protection and processing of personal data”) entails risks such as:
- loss of control over the transferred personal data,
- loss of privacy,
- lack of knowledge about the onward transfer of the personal data provided to other entities,
- failure to provide further information about the purposes for which the personal data will be further processed,
- misuse and identity theft,
- provision of the obtained personal data to security agencies and intelligence services (e.g. Russian Federation, USA, China),
- inability to exercise data subjects’ rights in the form guaranteed by the European GDPR against a controller based in a third country.
This processing does not involve automated individual decision-making, including profiling.
General and Additional Information on the Processing of Personal Data by the Controller
Technical and organisational measures:
Organisational and technical measures for the protection of personal data are set out in the controller’s internal regulations. Security measures are implemented in the areas of physical and premises security, information security, cryptographic protection of information, personnel and administrative security, and the protection of sensitive information, with precisely defined powers and responsibilities set out in the security policy.
Categories of personal data:
For the purposes mentioned above, we process ordinary personal data.
Publication of personal data:
Personal data are not published for any of the purposes mentioned above.
Automated processing including profiling:
The controller does not use automated decision-making or profiling when processing personal data.
Rights of data subjects:
The data subject has the right to request from the controller access to the personal data processed about them, the right to rectification of personal data, the right to erasure or restriction of processing of personal data, the right to object to the processing of personal data, the right not to be subject to automated individual decision-making, including profiling, the right to data portability, and the right to file a petition to initiate proceedings with the supervisory authority. Where the controller processes personal data on the basis of the data subject’s consent, the data subject has the right to withdraw their consent to the processing of personal data at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. The data subject may exercise their rights by sending an email to the controller’s email address or in writing to the controller’s postal address. Requests from data subjects are handled individually by a person designated by the controller.
As a data subject, you have the right to lodge a complaint with the supervisory authority if you believe that your rights relating to personal data have been violated. The supervisory authority is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava.
Recipients of personal data and other authorised entities:
Recipients of personal data:
| Registry management | Ministry of the Interior of the Slovak Republic (relevant archive)
|
| Accounting documents | Tax Office
|
| E-shop | Slovak Parcel Service s.r.o. GLS General Logistics Systems Slovakia s.r.o.
|
| Cookies | Google, Vimeo, Microsoft Clarity, YouTube, DoubleClick, Facebook
|
Other authorised entities:
| Other authorised entity | pursuant to Article 6(1)(c) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). |
| State authorities, public authorities and other entities specified by law | pursuant to Article 6(1)(c) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). |
Note: This Privacy Policy is a translation of the original Slovak version. The Slovak version is the primary version, and in the event of any discrepancy between the language versions, the Slovak version shall prevail.