Effective from: 01.08.2026
This policy explains what personal data we collect through leis-design.com, why we collect
it, what we do with it and what rights you have. It is written to meet Regulation (EU)
2016/679 (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).
Cookies and similar technologies are covered separately in our
Cookie Policy.
1. Who is responsible for your data
The controller of your personal data is:
RIMARKET d.o.o.
Jurjevica 50, Jurjevica, 1310 Ribnica, Slovenia, EU
Registration number: 3360563000
VAT identification number: SI41578562
Email: info@leis-design.com
Telephone: +386 51 726 150
For any question about your data, write to info@leis-design.com with the subject line
“Privacy”.
Data protection officer: [TO BE CONFIRMED BY OWNER: we do not believe a DPO is required
under Article 37 GDPR, because our core activity is not large scale monitoring or large
scale processing of special category data. Confirm that no DPO is appointed, or supply the
DPO’s contact details.]
2. Short version
| What | Why | Legal basis | How long |
|---|---|---|---|
| Order and delivery data | To make and deliver your order | Contract, Art. 6(1)(b) | 10 years, tax law |
| Payment data at Stripe or PayPal | To take payment | Contract, Art. 6(1)(b) | Held by the payment provider under its own policy |
| Invoice data | Because tax law says so | Legal obligation, Art. 6(1)(c) | 10 years |
| Emails you send us | To answer you | Contract or legitimate interest, Art. 6(1)(b) or (f) | 2 years |
| Analytics cookies | To see what works on the site | Consent, Art. 6(1)(a) | Up to 14 months |
| Advertising cookies and Meta measurement | To measure and target advertising | Consent, Art. 6(1)(a) | Up to 3 months per cookie |
| Consent record | To prove you consented | Legal obligation, Art. 6(1)(c) | Up to 12 months |
| Server and security logs | To keep the site working and safe | Legitimate interest, Art. 6(1)(f) | [TO BE CONFIRMED BY OWNER: hosting log retention] |
We do not sell your personal data. We do not run a newsletter. We do not create customer
accounts. There is no login area on this site.
3. What we collect and why
3.1 When you place an order
We collect what we need to conclude and perform the contract:
- first name and surname
- delivery address, meaning street, house number, city, postcode and country
- email address
- telephone number, which the carrier needs to arrange delivery
- company name and VAT identification number, only if you enter them
- order contents, quantity, price, discount, delivery cost and total
- order number, order date and order status
- the advertising variant identifier (see section 3.5)
Legal basis: performance of a contract, Article 6(1)(b) GDPR. Without this data we
cannot conclude or deliver the order.
Retention: order data and the invoice are kept for 10 years from the end of the year
in which the invoice was issued, as required by the Slovenian VAT Act and accounting rules.
3.2 Payment
We never see or store your full card number. Card details are entered directly into
fields provided by the payment provider and go straight to the provider over an encrypted
connection.
We use:
- Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin,
Ireland, for card payments, Apple Pay, Google Pay and Link - PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, for
PayPal payments
For payment data, Stripe and PayPal act as independent controllers, not as our
processors. They process your data under their own privacy policies and their own legal
obligations, including anti money laundering and fraud prevention rules.
What we receive back from them is limited to the payment status, the transaction reference,
the payment method type and the last four digits of the card, so that we can match the
payment to your order and process refunds.
- Stripe privacy policy: https://stripe.com/privacy
- PayPal privacy statement: https://www.paypal.com/privacy
Legal basis: performance of a contract, Article 6(1)(b) GDPR.
3.3 Delivery
We pass your name, delivery address, email address and telephone number to our carrier so
the parcel can be delivered and so the carrier can contact you about the delivery window.
Carrier: General Logistics Systems (GLS), delivering from our dispatch point in Slovenia.
Legal basis: performance of a contract, Article 6(1)(b) GDPR.
3.4 When you contact us
If you email us or call us, we process your message, your contact details and anything else
you choose to tell us, in order to answer you and to keep a record of complaints.
Legal basis: performance of a contract where your message concerns an order, Article
6(1)(b). Otherwise our legitimate interest in answering enquiries and in being able to prove
how a complaint was handled, Article 6(1)(f).
Retention: 2 years from the last message in the thread, or longer where the matter could
still lead to a legal claim.
3.5 Advertising variants on the website
Our website shows different headlines, images and text depending on which advertisement you
came from. Which version you see is decided by a parameter in the link you clicked, and it
is remembered in a cookie named leis_angle for up to 30 days so that the same version
stays visible while you browse.
The identifier is a short label such as gift or magnet. It describes the advertisement,
not you. It contains no name, no email and no device fingerprint.
If you place an order, this identifier is stored with the order so we can see which
advertising message produced which sale.
This never changes your price, your discount or your delivery cost.
Legal basis: our legitimate interest in measuring which advertising works, Article
6(1)(f). Where consent is required for storing the cookie itself, that is handled by the
consent banner and described in the Cookie Policy.
Retention: cookie for up to 30 days. As part of the order record, for as long as the
order record is kept.
3.6 Analytics and advertising
Nothing loads until you consent. Google Tag Manager, Google Analytics 4 and the Meta
Pixel are not loaded at all until you accept the relevant cookie categories in the consent
banner. If you decline, no analytics or advertising script runs and no such cookie is set.
Where you consent, we use:
- Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street,
Dublin 4, Ireland. Used to understand how visitors use the site and which pages and
sections lead to a purchase. IP addresses are shortened by Google before storage. - Meta Pixel and the Meta Conversions API, provided by Meta Platforms Ireland Limited,
Merrion Road, Dublin 4, Ireland. Used to measure the results of our advertising on
Facebook and Instagram and to show relevant advertising.
The Meta Conversions API sends event data from our server to Meta. Where it includes contact
details such as your email address, those are hashed before transmission. Meta uses them
to match the event to an account. This happens only where you have consented to the
marketing cookie category.
We also use Google Consent Mode v2, which tells Google whether you consented, so that
Google’s tags adjust their behaviour accordingly.
Legal basis: your consent, Article 6(1)(a) GDPR, together with Article 5(3) of the
ePrivacy Directive as implemented in Slovenian law. You can withdraw consent at any time.
Retention: as stated in the Cookie Policy, and in Google’s and
Meta’s own retention settings. Our Google Analytics data retention is set to
[TO BE CONFIRMED BY OWNER: 14 months is the recommended setting].
- Google privacy policy: https://policies.google.com/privacy
- Meta privacy policy: https://www.facebook.com/privacy/policy
3.7 Consent records
When you make a choice in the cookie banner, we store a record of that choice, including
which categories you accepted and when. This is needed to prove that consent was given, as
Article 7(1) GDPR requires.
Legal basis: legal obligation, Article 6(1)(c) GDPR.
Retention: up to 12 months, after which we ask again.
3.8 Server logs and security
Our hosting provider records technical data with every request, typically the IP address,
the date and time, the requested address, the referring page, the browser and the operating
system. This is needed to run the site, to detect attacks and to investigate faults.
Legal basis: our legitimate interest in the security and availability of the website,
Article 6(1)(f) GDPR.
Retention: [TO BE CONFIRMED BY OWNER: the log retention period set by the hosting
provider].
3.9 Emails we send you
We send transactional emails only:
- order confirmation
- dispatch notification with tracking
- messages about a return, a refund or a complaint
We do not send marketing emails and we do not operate a newsletter. There is no email
signup field anywhere on this website and there is no popup asking for your address.
Legal basis: performance of a contract, Article 6(1)(b) GDPR.
4. What we do not do
- We do not sell or rent personal data.
- We do not run a newsletter or any email marketing.
- We do not create user accounts. Checkout is guest only.
- We do not collect special category data as defined in Article 9 GDPR.
- We do not carry out automated decision making or profiling that produces legal effects for
you or similarly significantly affects you, within the meaning of Article 22 GDPR. - We do not use personalised pricing. Everyone sees the same price.
- We do not knowingly collect data from children. This site is aimed at adults and orders
may only be placed by persons with legal capacity to contract.
5. Who we share data with
We share personal data only where it is necessary, and only with:
| Recipient | Role | What they receive | Where |
|---|---|---|---|
| Hosting provider, Domenca | Processor | Everything stored on the server, including order data | Slovenia, EU |
| Stripe Payments Europe, Limited | Independent controller | Payment and card data | Ireland, EU |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Independent controller | Payment data | Luxembourg, EU |
| GLS | Processor or independent controller depending on the service | Name, address, email, telephone | Slovenia and destination country, EU |
| Email sending provider (SMTP) | Processor | Email address and message content | [TO BE CONFIRMED BY OWNER: which SMTP provider is used and where it is located] |
| Accounting and invoicing provider | Processor | Invoice data | [TO BE CONFIRMED BY OWNER: which invoicing system is used] |
| Google Ireland Limited | Processor for analytics | Usage data, with consent only | Ireland, EU, with transfers to the USA |
| Meta Platforms Ireland Limited | Joint controller for pixel measurement | Event data, with consent only | Ireland, EU, with transfers to the USA |
We also disclose data where we are legally required to, for example to tax authorities, to
the police or to a court.
Every processor works under a written data processing agreement under Article 28 GDPR.
[TO BE CONFIRMED BY OWNER: confirm that signed data processing agreements are in place with
the hosting provider, the SMTP provider and the accounting provider before launch.]
6. Transfers outside the EU
Order fulfilment, hosting, payment and delivery all stay inside the European Union.
Google and Meta may transfer data to the United States. Those transfers rely on:
- the European Commission’s adequacy decision of 10 July 2023 for the EU-US Data Privacy
Framework, where the recipient is certified under it, and - Standard Contractual Clauses under Article 46(2)(c) GDPR, together with supplementary
measures, where it is not.
These transfers only happen if you consent to the relevant cookie categories. If you decline
analytics and marketing cookies, no data goes to Google or Meta.
7. How long we keep data
| Data | Retention | Reason |
|---|---|---|
| Orders, invoices, accounting records | 10 years from the end of the year the invoice was issued | Slovenian VAT and accounting law |
| Withdrawal, return and complaint records | 5 years from closure | Limitation period for claims |
| Support emails without an order | 2 years from the last message | Legitimate interest |
| Consent records | Up to 12 months | Proof of consent under Article 7 GDPR |
| Analytics data | Up to 14 months, subject to confirmation | Analytics retention setting |
| Advertising cookies | Up to 3 months per cookie | See Cookie Policy |
| Server logs | [TO BE CONFIRMED BY OWNER] | Security |
When the retention period ends, data is deleted or irreversibly anonymised.
8. Your rights
Under the GDPR you have the right to:
- Access. Get confirmation of whether we process your data and receive a copy of it.
- Rectification. Have inaccurate data corrected and incomplete data completed.
- Erasure. Have your data deleted, where one of the grounds in Article 17 applies. Note
that we cannot delete invoices and order records before the tax retention period ends. - Restriction. Have processing limited in the cases listed in Article 18.
- Data portability. Receive the data you gave us in a structured, commonly used,
machine readable format and have it transmitted to another controller where technically
feasible. - Object. Object at any time to processing based on our legitimate interest, on grounds
relating to your particular situation. Where the processing is for direct marketing, you
may object at any time and we must stop. - Withdraw consent. Withdraw consent at any time, with no effect on the lawfulness of
processing before the withdrawal. For cookies, use the cookie settings link in the footer. - Complain. Lodge a complaint with a supervisory authority.
How to exercise a right
Email info@leis-design.com with the subject line “GDPR request” and tell us what you
want. We answer within one month. If the request is complex we may extend this by two
further months and we will tell you why within the first month.
Exercising a right is free of charge. For manifestly unfounded or excessive requests we may
charge a reasonable fee or refuse, as Article 12(5) GDPR allows.
We may ask for information to confirm your identity, so that we do not give your data to
somebody else.
Supervisory authority
Informacijski pooblaščenec (Information Commissioner of the Republic of Slovenia)
Dunajska cesta 22, 1000 Ljubljana, Slovenia
Email: gp.ip@ip-rs.si
Telephone: +386 1 230 97 30
Website: https://www.ip-rs.si
You may also complain to the supervisory authority in the EU country where you live or work.
9. Security
We apply appropriate technical and organisational measures under Article 32 GDPR, including:
- encrypted transport for the whole site and the checkout, using HTTPS with a valid TLS
certificate - card data handled entirely by PCI DSS compliant payment providers, never on our server
- access to the shop administration restricted to named accounts with strong passwords
- regular updates of the platform, the theme and the plugins
- backups held by the hosting provider
No system is perfectly secure. If a personal data breach occurs that is likely to result in
a high risk to your rights and freedoms, we will notify you without undue delay, and we will
notify the Information Commissioner within 72 hours as Article 33 GDPR requires.
10. Third party links
Our website may link to external sites, for example a payment provider or a social network.
We are not responsible for the privacy practices of those sites. Please read their own
privacy policies.
11. Changes to this policy
We may update this policy, for example when we add a service or change a provider. The
effective date at the top always shows the current version. Where a change materially
affects you, we will make it visible on the website.
RIMARKET d.o.o., Jurjevica 50, Jurjevica, 1310 Ribnica, Slovenia. Registration number
3360563000. VAT SI41578562.