PROVIDING INFORMATION UNDER THE PERSONAL DATA PROTECTION ACT
Pursuant to Act No. 18/2018 Coll. on the protection of personal data and on amendments to certain laws, as well as in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), we hereby provide you with information on the processing of your personal data.
WHO PROCESSES YOUR PERSONAL DATA?
The data controller is TROFIO a.s., Odbojárov 3, 831 04 Bratislava, Company ID: 45 562 903, registered in the Commercial Register of the District Court Bratislava III, Section Sa, Insert No. 5030/B (hereinafter “TROFIO”).
WHAT PERSONAL DATA DO WE PROCESS?
Contact form, email, or phone communication:
If you contact us via a contact form, email, or phone, we process:
your contact details (e.g., name, email, phone),
the content of your message or request.
These data are used to handle your requests or respond to your questions.
Legal basis: our legitimate interest under Art. 6(1)(f) GDPR.
Retention period: 3 months from handling the request. If an order arises from the communication, personal data are processed further according to the above rules.
If necessary to protect legal claims, we may retain data for 3 years and 1 year thereafter, especially if a complaint was submitted at the end of the limitation period. In case of legal proceedings, we retain data during the proceedings and for the remaining limitation period afterward. You have the right to object to processing based on legitimate interest.
Newsletter / email marketing:
If you have given us consent to receive marketing information (e.g., newsletters), we process:
your email address,
optionally your first and last name (if provided during registration or order).
These data are processed for the purpose of sending information about our products, promotions, news, and other marketing activities.
Legal basis: consent of the data subject under Art. 6(1)(a) GDPR.
Retention period: until withdrawal of consent. You can unsubscribe from newsletters at any time by clicking the link at the bottom of each email or by contacting the controller.
Competitions and marketing campaigns:
If you participate in a competition organized via our website or social media, we process:
first and last name,
email address,
delivery address (if needed to send the prize),
other data you provide during participation.
These data are necessary to conduct the competition, contact winners, and deliver prizes.
Legal basis: consent of the data subject under Art. 6(1)(a) GDPR, or performance of a contract.
Retention period: during the competition and a maximum of 6 months after its end, unless a longer period is required by law.
Product reviews and ratings:
If you voluntarily provide a review of a product or service, we process:
name or nickname,
content of the review or comment.
These data are used to publish the review on our website or other promotional channels.
Legal basis: consent of the data subject under Art. 6(1)(a) GDPR.
Retention period: until withdrawal of consent or deletion of the review.
COOKIES
TROFIO uses cookies on the website www.trofiostars.com, which are necessary for the proper functioning of the site and the provision of our services.
We use the following types of cookies:
Necessary cookies – technically required for the website to function. They are automatically deleted after closing the website and provide only non-personal statistical data about traffic, e.g., number of visitors or visit duration.
Functional cookies – allow remembering login details and secure login. They also help adjust the web interface according to your preferences.
Third-party cookies – generated exclusively by external service providers that TROFIO cannot read or influence. For example:
Analytical cookies (e.g., Google Analytics) – measure user behavior to improve website functionality and content,
Social media (Facebook, Instagram, YouTube, etc.) – enable content sharing and display of targeted ads.
Managing cookie consent:
On your first visit to our site, you can give or refuse consent for certain types of cookies (except necessary ones). You can withdraw this consent or change settings at any time via your browser or via the cookie management tool available on our website.
DATA RETENTION / SECURITY
We process your personal data for the necessary period, i.e., only as long as the purpose of processing lasts, or until withdrawal of the consent if processing is based on consent. After this period, personal data are deleted or anonymized, unless further retention is required by law (e.g., accounting law).
We protect the personal data in our possession to the greatest extent against leakage, misuse, or damage. Files containing personal data are password-protected, and access is limited to a small number of employees and collaborators trained in data protection and how to handle and secure such data.
WHO ELSE MAY HAVE ACCESS TO YOUR DATA?
Your personal data may be accessed by TROFIO as the controller, its employees, and contractual intermediaries, mainly companies providing IT services, programming services, e-shop management, and accounting.
Your personal data may also be made available to third parties, such as delivery companies that ensure the transport of your order. These entities act as independent controllers or contractual intermediaries under Article 28 GDPR and are contractually bound to confidentiality and compliance with data protection principles.
WHAT ARE YOUR RIGHTS?
As a data subject, you can exercise the following rights regarding your personal data processing:
Information about data processing:
Includes identification and contact details of the controller, its representative, and data protection officer (if applicable), purposes of processing, categories of personal data, recipients or categories of recipients, information on transfer to third countries, retention periods, authorized controllers, list of your rights, ability to contact the Office for Personal Data Protection, source of the processed data, and information on automated decision-making and profiling. This information will be provided upon request or at the time of collection.
Right of access:
You have the right to receive a copy of your personal data and information on how we use it. If requested electronically, the information will be provided electronically if technically feasible.
Right to rectification:
If we process inaccurate or outdated personal data (e.g., changed your address), please inform us, and we will correct your data.
Right to data portability:
If you wish, we will provide your personal data to another company in a suitable format, provided processing is based on your consent or a contract and is carried out by automated means.
Right to erasure:
In certain cases required by law, we are obliged to delete your personal data at your instruction. This applies especially when:
data are no longer necessary for the purposes collected,
you withdraw consent and no other legal basis exists,
processing was unlawful.
Right to restriction of processing:
You may request restriction if:
you contest data accuracy,
processing is unlawful but you do not want deletion,
the controller no longer needs the data but you need them for legal claims,
you object and it is pending verification whether legitimate interests prevail.
Right to file a complaint:
You can file a complaint regarding personal data processing at any time with the supervisory authority, the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, tel.: +421/2/3231 324, email: statny.dozor@pdp.gov.sk, https://dataprotection.gov.sk/uoou/. For electronic submissions, they must comply with the requirements of §19(1) of Act No. 71/1967 Coll. on Administrative Proceedings (Administrative Code).