Privacy and Cookies Policy
(Date of last update: 02.09.2025)
Your privacy is our priority. In this document, we clearly explain how we handle your personal data, for what purposes we use it, to whom we may disclose it, and what rights you have as a data subject. The processing of data is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter referred to as the “GDPR”) and the relevant national legislation – Act No. 18/2018 Coll. on the Protection of Personal Data and on Amendments and Supplements to Certain Acts.
1. Data Controller
1.1. The controller of your personal data is: NELA BALAS, s.r.o.
Registered office: Rozvoj 1373/14, 054 01 Levoča
Company ID No.: 57 129 533
Tax ID No.: 21 22 577 270
Represented by: Mgr. Petronela Balášová
E-mail: info@nelabalas.com
Phone: +421 903 780 101
1.2. This entity determines why and how your personal data will be processed and is therefore responsible for its protection.
2. What data do we process and for what purpose?
2.1. We process only those data that are necessary for the fulfilment of our contractual and legal obligations or that you have provided to us on the basis of consent. Specifically, this includes:
- Identification data – first name, last name, delivery address (e.g. for issuing invoices, delivering goods),
- Contact data – e-mail, telephone number (for order confirmation, complaints, communication),
- Payment data – account number, transaction information (only to the necessary extent),
- Technical data – IP address, cookies, device and browser information.
2.2. We process the data primarily for the following purposes:
- processing of the order and conclusion of the purchase contract (Art. 6(1)(b) GDPR),
- delivery of goods,
- issuing of tax documents and fulfilment of legal obligations (Art. 6(1)(c) GDPR),
- handling of complaints and disputes,
- sending of marketing communications based on your consent (Art. 6(1)(a) GDPR),
- protection of legal interests, prevention of fraud and misuse (Art. 6(1)(f) GDPR).
3. Legal bases for processing
Every processing of personal data is based on a specific legal ground pursuant to Art. 6 GDPR:
- performance of a contract – processing is necessary for the performance of a contract with you,
- legal obligation – e.g. accounting, tax obligations,
- legitimate interest – e.g. for the protection of rights or for direct marketing (where consent is not required),
- consent of the data subject – for newsletter registration or analytical cookies.
4. To whom may we disclose the data?
4.1. We disclose your data only when necessary:
- to carriers (courier companies, Packeta, Slovenská pošta),
- to payment service providers (e.g. Comgate, banks),
- to IT service providers (hosting, e-shop management, mailing),
- to accounting and tax advisors,
- to public institutions, where required by law.
4.2. We have concluded data processing agreements with all processors pursuant to Art. 28 GDPR.
5. How long do we retain your data?
The retention period depends on the purpose of processing:
- for the duration of the contractual relationship,
- accounting and tax data – minimum of 10 years,
- data for marketing purposes – until consent is withdrawn, maximum 5 years,
- data related to complaints – 2 years from resolution.
6. Your rights under the GDPR
You have the right:
- to access personal data (Art. 15 GDPR),
- to rectification of inaccurate data (Art. 16 GDPR),
- to erasure of data (“right to be forgotten”, Art. 17 GDPR),
- to restriction of processing (Art. 18 GDPR),
- to data portability to another controller (Art. 20 GDPR),
- to object to processing (Art. 21 GDPR),
- to withdraw consent (if given – Art. 7 GDPR),
- to lodge a complaint with a supervisory authority – see section 10, “Contacts of supervisory authorities”
7. Data security
We use technical and organisational measures to protect data against loss, misuse and unauthorised access – including encryption, access restriction, secure backup and audits.
8. Cookies and tracking technologies
8.1. What are cookies?
Cookies are small text files stored on your device that enable the website to recognise you as a visitor, remember your preferences or analyse traffic.
8.2. Types of cookies we use:
- Necessary – required for the functioning of the website (e.g. login, shopping cart),
- Preference – remember your settings (e.g. language or location),
- Statistical – anonymously measure traffic (e.g. via Google Analytics),
- Marketing – enable the display of personalised advertising based on your preferences and previous activity (e.g. via Meta Pixel).
8.3. Consent to the use of cookies
8.3.1. Upon the first visit to the website, a cookie banner is displayed where you have the option to:
- accept all cookies,
- reject non-essential cookies,
- individually set your preferences.
8.3.2. Necessary cookies are stored without the need for consent (Art. 6(1)(f) GDPR).
8.4. Cookie management
You can adjust or delete cookie settings at any time via your browser. Restricting cookies may, however, affect the functionality of the website.
8.5. Third-party cookies
Our website may contain third-party cookies (e.g. Google, Facebook, Instagram) that track your behaviour across different websites. These entities act as independent controllers.
8.6. Cookie retention period
Each type of cookie has a defined retention period. Some are deleted after the browser is closed (session cookies), others remain on the device for a longer period (persistent cookies). The exact duration can be found in your browser settings or in the consent management tool.
9. Automated decision-making and profiling
We do not carry out automated decision-making or profiling within the meaning of Art. 22 GDPR.
10. Cross-border processing and contact details of supervisory authorities
10.1. NELA BALAS, s.r.o. is established in the Slovak Republic and, as the controller of personal data when selling goods to customers from several Member States of the European Union, carries out so-called cross-border processing of data within the meaning of Art. 4(23) GDPR. In accordance with Articles 56 and 60 GDPR, the lead supervisory authority for the protection of personal data is therefore the Úrad na ochranu osobných údajov of the Slovak Republic, which is responsible for supervising the processing of data, including cross-border activities.
10.2. Customers from other EU Member States may, in the event of a suspected infringement of the GDPR, contact either the Slovak supervisory authority directly or the supervisory authority of their own country, which will then forward the complaint under the cooperation mechanism between Member States pursuant to the GDPR.
Contacts of supervisory authorities within the European Union:
-
Slovakia – Úrad na ochranu osobných údajov
Námestie 1. mája 18, 811 06 Bratislava
www.dataprotection.gov.sk -
Czech Republic – Úřad pro ochranu osobních údajů
Pplk. Sochora 27, 170 00 Praha 7
www.uoou.cz -
Poland – Urząd Ochrony Danych Osobowych
ul. Stawki 2, 00-193 Warszawa
uodo.gov.pl -
Austria – Österreichische Datenschutzbehörde
Barichgasse 40-42, 1030 Wien
www.dsb.gv.at -
Hungary – Nemzeti Adatvédelmi és Információszabadság Hatóság
Falk Miksa utca 9-11, 1055 Budapest
www.naih.hu -
Germany – Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit
Graurheindorfer Straße 153, 53117 Bonn
www.bfdi.bund.de -
Romania – Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București
www.dataprotection.ro -
Cyprus – Γραφείο Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα
Iasonos 1, 1082 Nicosia
www.dataprotection.gov.cy -
Ireland – Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28
www.dataprotection.ie
If you have any further questions regarding the processing of personal data, please contact us by e-mail.