Effective from: 01.08.2026

This policy explains what personal data we collect through leis-design.com, why we collect
it, what we do with it and what rights you have. It is written to meet Regulation (EU)
2016/679 (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).

Cookies and similar technologies are covered separately in our
Cookie Policy.


1. Who is responsible for your data

The controller of your personal data is:

RIMARKET d.o.o.
Jurjevica 50, Jurjevica, 1310 Ribnica, Slovenia, EU
Registration number: 3360563000
VAT identification number: SI41578562

Email: info@leis-design.com
Telephone: +386 51 726 150

For any question about your data, write to info@leis-design.com with the subject line
“Privacy”.

Data protection officer: [TO BE CONFIRMED BY OWNER: we do not believe a DPO is required
under Article 37 GDPR, because our core activity is not large scale monitoring or large
scale processing of special category data. Confirm that no DPO is appointed, or supply the
DPO’s contact details.]


2. Short version

What Why Legal basis How long
Order and delivery data To make and deliver your order Contract, Art. 6(1)(b) 10 years, tax law
Payment data at Stripe or PayPal To take payment Contract, Art. 6(1)(b) Held by the payment provider under its own policy
Invoice data Because tax law says so Legal obligation, Art. 6(1)(c) 10 years
Emails you send us To answer you Contract or legitimate interest, Art. 6(1)(b) or (f) 2 years
Analytics cookies To see what works on the site Consent, Art. 6(1)(a) Up to 14 months
Advertising cookies and Meta measurement To measure and target advertising Consent, Art. 6(1)(a) Up to 3 months per cookie
Consent record To prove you consented Legal obligation, Art. 6(1)(c) Up to 12 months
Server and security logs To keep the site working and safe Legitimate interest, Art. 6(1)(f) [TO BE CONFIRMED BY OWNER: hosting log retention]

We do not sell your personal data. We do not run a newsletter. We do not create customer
accounts. There is no login area on this site.


3. What we collect and why

3.1 When you place an order

We collect what we need to conclude and perform the contract:

  • first name and surname
  • delivery address, meaning street, house number, city, postcode and country
  • email address
  • telephone number, which the carrier needs to arrange delivery
  • company name and VAT identification number, only if you enter them
  • order contents, quantity, price, discount, delivery cost and total
  • order number, order date and order status
  • the advertising variant identifier (see section 3.5)

Legal basis: performance of a contract, Article 6(1)(b) GDPR. Without this data we
cannot conclude or deliver the order.

Retention: order data and the invoice are kept for 10 years from the end of the year
in which the invoice was issued, as required by the Slovenian VAT Act and accounting rules.

3.2 Payment

We never see or store your full card number. Card details are entered directly into
fields provided by the payment provider and go straight to the provider over an encrypted
connection.

We use:

  • Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin,
    Ireland, for card payments, Apple Pay, Google Pay and Link
  • PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, for
    PayPal payments

For payment data, Stripe and PayPal act as independent controllers, not as our
processors. They process your data under their own privacy policies and their own legal
obligations, including anti money laundering and fraud prevention rules.

What we receive back from them is limited to the payment status, the transaction reference,
the payment method type and the last four digits of the card, so that we can match the
payment to your order and process refunds.

  • Stripe privacy policy: https://stripe.com/privacy
  • PayPal privacy statement: https://www.paypal.com/privacy

Legal basis: performance of a contract, Article 6(1)(b) GDPR.

3.3 Delivery

We pass your name, delivery address, email address and telephone number to our carrier so
the parcel can be delivered and so the carrier can contact you about the delivery window.

Carrier: General Logistics Systems (GLS), delivering from our dispatch point in Slovenia.

Legal basis: performance of a contract, Article 6(1)(b) GDPR.

3.4 When you contact us

If you email us or call us, we process your message, your contact details and anything else
you choose to tell us, in order to answer you and to keep a record of complaints.

Legal basis: performance of a contract where your message concerns an order, Article
6(1)(b). Otherwise our legitimate interest in answering enquiries and in being able to prove
how a complaint was handled, Article 6(1)(f).

Retention: 2 years from the last message in the thread, or longer where the matter could
still lead to a legal claim.

3.5 Advertising variants on the website

Our website shows different headlines, images and text depending on which advertisement you
came from. Which version you see is decided by a parameter in the link you clicked, and it
is remembered in a cookie named leis_angle for up to 30 days so that the same version
stays visible while you browse.

The identifier is a short label such as gift or magnet. It describes the advertisement,
not you. It contains no name, no email and no device fingerprint.

If you place an order, this identifier is stored with the order so we can see which
advertising message produced which sale.

This never changes your price, your discount or your delivery cost.

Legal basis: our legitimate interest in measuring which advertising works, Article
6(1)(f). Where consent is required for storing the cookie itself, that is handled by the
consent banner and described in the Cookie Policy.

Retention: cookie for up to 30 days. As part of the order record, for as long as the
order record is kept.

3.6 Analytics and advertising

Nothing loads until you consent. Google Tag Manager, Google Analytics 4 and the Meta
Pixel are not loaded at all until you accept the relevant cookie categories in the consent
banner. If you decline, no analytics or advertising script runs and no such cookie is set.

Where you consent, we use:

  • Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street,
    Dublin 4, Ireland. Used to understand how visitors use the site and which pages and
    sections lead to a purchase. IP addresses are shortened by Google before storage.
  • Meta Pixel and the Meta Conversions API, provided by Meta Platforms Ireland Limited,
    Merrion Road, Dublin 4, Ireland. Used to measure the results of our advertising on
    Facebook and Instagram and to show relevant advertising.

The Meta Conversions API sends event data from our server to Meta. Where it includes contact
details such as your email address, those are hashed before transmission. Meta uses them
to match the event to an account. This happens only where you have consented to the
marketing cookie category.

We also use Google Consent Mode v2, which tells Google whether you consented, so that
Google’s tags adjust their behaviour accordingly.

Legal basis: your consent, Article 6(1)(a) GDPR, together with Article 5(3) of the
ePrivacy Directive as implemented in Slovenian law. You can withdraw consent at any time.

Retention: as stated in the Cookie Policy, and in Google’s and
Meta’s own retention settings. Our Google Analytics data retention is set to
[TO BE CONFIRMED BY OWNER: 14 months is the recommended setting].

  • Google privacy policy: https://policies.google.com/privacy
  • Meta privacy policy: https://www.facebook.com/privacy/policy

3.7 Consent records

When you make a choice in the cookie banner, we store a record of that choice, including
which categories you accepted and when. This is needed to prove that consent was given, as
Article 7(1) GDPR requires.

Legal basis: legal obligation, Article 6(1)(c) GDPR.

Retention: up to 12 months, after which we ask again.

3.8 Server logs and security

Our hosting provider records technical data with every request, typically the IP address,
the date and time, the requested address, the referring page, the browser and the operating
system. This is needed to run the site, to detect attacks and to investigate faults.

Legal basis: our legitimate interest in the security and availability of the website,
Article 6(1)(f) GDPR.

Retention: [TO BE CONFIRMED BY OWNER: the log retention period set by the hosting
provider].

3.9 Emails we send you

We send transactional emails only:

  • order confirmation
  • dispatch notification with tracking
  • messages about a return, a refund or a complaint

We do not send marketing emails and we do not operate a newsletter. There is no email
signup field anywhere on this website and there is no popup asking for your address.

Legal basis: performance of a contract, Article 6(1)(b) GDPR.


4. What we do not do

  • We do not sell or rent personal data.
  • We do not run a newsletter or any email marketing.
  • We do not create user accounts. Checkout is guest only.
  • We do not collect special category data as defined in Article 9 GDPR.
  • We do not carry out automated decision making or profiling that produces legal effects for
    you or similarly significantly affects you, within the meaning of Article 22 GDPR.
  • We do not use personalised pricing. Everyone sees the same price.
  • We do not knowingly collect data from children. This site is aimed at adults and orders
    may only be placed by persons with legal capacity to contract.

5. Who we share data with

We share personal data only where it is necessary, and only with:

Recipient Role What they receive Where
Hosting provider, Domenca Processor Everything stored on the server, including order data Slovenia, EU
Stripe Payments Europe, Limited Independent controller Payment and card data Ireland, EU
PayPal (Europe) S.à r.l. et Cie, S.C.A. Independent controller Payment data Luxembourg, EU
GLS Processor or independent controller depending on the service Name, address, email, telephone Slovenia and destination country, EU
Email sending provider (SMTP) Processor Email address and message content [TO BE CONFIRMED BY OWNER: which SMTP provider is used and where it is located]
Accounting and invoicing provider Processor Invoice data [TO BE CONFIRMED BY OWNER: which invoicing system is used]
Google Ireland Limited Processor for analytics Usage data, with consent only Ireland, EU, with transfers to the USA
Meta Platforms Ireland Limited Joint controller for pixel measurement Event data, with consent only Ireland, EU, with transfers to the USA

We also disclose data where we are legally required to, for example to tax authorities, to
the police or to a court.

Every processor works under a written data processing agreement under Article 28 GDPR.

[TO BE CONFIRMED BY OWNER: confirm that signed data processing agreements are in place with
the hosting provider, the SMTP provider and the accounting provider before launch.]


6. Transfers outside the EU

Order fulfilment, hosting, payment and delivery all stay inside the European Union.

Google and Meta may transfer data to the United States. Those transfers rely on:

  • the European Commission’s adequacy decision of 10 July 2023 for the EU-US Data Privacy
    Framework
    , where the recipient is certified under it, and
  • Standard Contractual Clauses under Article 46(2)(c) GDPR, together with supplementary
    measures, where it is not.

These transfers only happen if you consent to the relevant cookie categories. If you decline
analytics and marketing cookies, no data goes to Google or Meta.


7. How long we keep data

Data Retention Reason
Orders, invoices, accounting records 10 years from the end of the year the invoice was issued Slovenian VAT and accounting law
Withdrawal, return and complaint records 5 years from closure Limitation period for claims
Support emails without an order 2 years from the last message Legitimate interest
Consent records Up to 12 months Proof of consent under Article 7 GDPR
Analytics data Up to 14 months, subject to confirmation Analytics retention setting
Advertising cookies Up to 3 months per cookie See Cookie Policy
Server logs [TO BE CONFIRMED BY OWNER] Security

When the retention period ends, data is deleted or irreversibly anonymised.


8. Your rights

Under the GDPR you have the right to:

  • Access. Get confirmation of whether we process your data and receive a copy of it.
  • Rectification. Have inaccurate data corrected and incomplete data completed.
  • Erasure. Have your data deleted, where one of the grounds in Article 17 applies. Note
    that we cannot delete invoices and order records before the tax retention period ends.
  • Restriction. Have processing limited in the cases listed in Article 18.
  • Data portability. Receive the data you gave us in a structured, commonly used,
    machine readable format and have it transmitted to another controller where technically
    feasible.
  • Object. Object at any time to processing based on our legitimate interest, on grounds
    relating to your particular situation. Where the processing is for direct marketing, you
    may object at any time and we must stop.
  • Withdraw consent. Withdraw consent at any time, with no effect on the lawfulness of
    processing before the withdrawal. For cookies, use the cookie settings link in the footer.
  • Complain. Lodge a complaint with a supervisory authority.

How to exercise a right

Email info@leis-design.com with the subject line “GDPR request” and tell us what you
want. We answer within one month. If the request is complex we may extend this by two
further months and we will tell you why within the first month.

Exercising a right is free of charge. For manifestly unfounded or excessive requests we may
charge a reasonable fee or refuse, as Article 12(5) GDPR allows.

We may ask for information to confirm your identity, so that we do not give your data to
somebody else.

Supervisory authority

Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia)
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Email: gp.ip@ip-rs.si
Telephone: +386 1 230 97 30
Website: https://www.ip-rs.si

You may also complain to the supervisory authority in the EU country where you live or work.


9. Security

We apply appropriate technical and organisational measures under Article 32 GDPR, including:

  • encrypted transport for the whole site and the checkout, using HTTPS with a valid TLS
    certificate
  • card data handled entirely by PCI DSS compliant payment providers, never on our server
  • access to the shop administration restricted to named accounts with strong passwords
  • regular updates of the platform, the theme and the plugins
  • backups held by the hosting provider

No system is perfectly secure. If a personal data breach occurs that is likely to result in
a high risk to your rights and freedoms, we will notify you without undue delay, and we will
notify the Information Commissioner within 72 hours as Article 33 GDPR requires.


10. Third party links

Our website may link to external sites, for example a payment provider or a social network.
We are not responsible for the privacy practices of those sites. Please read their own
privacy policies.


11. Changes to this policy

We may update this policy, for example when we add a service or change a provider. The
effective date at the top always shows the current version. Where a change materially
affects you, we will make it visible on the website.


RIMARKET d.o.o., Jurjevica 50, Jurjevica, 1310 Ribnica, Slovenia. Registration number
3360563000. VAT SI41578562.