Privacy policy and protection of your personal data

In the following data protection information, we inform you about the processing of personal data on the Gripnatic website, which is carried out by the company Lipra, razvoj, proizvodja in prodaja d.o.o. (hereinafter: “Gripnatic” and/or “controller”) under the General Data Protection Regulation and individual applicable laws on the protection of personal data.

Company information:

Name: LIPRA d.o.o.

Address: Turnse 45, 1233 Dob, Slovenia

Tax number: SI27669009

Registration number: 9455078000

TRR: SI56 0284 3026 5538 068

T: +386 (0)51 824 159

M: contact@gripnatic.com

1. General

We are committed to protecting the confidentiality of your personal data in accordance with the law. We will do everything necessary to protect you from any violations and abuses. Users’ personal data is one of the areas to which we pay extreme care and attention, as we are aware of the sensitive nature of this area.

2. Implementation of the privacy policy

All persons employed full-time or part-time by us who have access to personal and other data of users are aware of the duty to protect personal and other data and are obliged to comply with the provisions on protecting the confidentiality of personal data and the privacy of users of the online store.

With companies that have the possibility of viewing personal data (accounting services – Epartner d.o.o., and the provider, administrator of the ERP and accounting system – Eurofaktura d.o.o.), we have signed a contract on the processing and protection of personal data from our records.

We have limited access to personal data and the scope of personal data to a minimum that still allows for optimal performance of services. The duty to protect personal and other data applies indefinitely, even after the termination of the relationship with us. For the highest possible level of protection of your personal data, the company has adopted the Rules on the protection of personal data with a record of their processing activities.

3. Type of data collected and the purpose of its collection

Every time you visit the Gripnatic website, in every purchase process, registration process, participation in prize games and promotions, subscription to e-newsletters and in the case of membership in the loyalty club, we request personal data from you, the provision of which is voluntary. Data related to the purchase process, participation in prize games, in the case of membership in the loyalty club and in other relevant contractual relationships, we also request data from you that we need for the realization of the mutual contract.

Each time you visit our website, information is sent to the server of our website/application via the individual web browser of your device and temporarily stored in so-called log files. The data records stored here contain the following data, which are kept until automatic deletion: date and time of access, name of the page accessed, IP address of the device sending the request, referring URL (source URL from which you came to our website), amount of data transferred, download time and information about the product and version of the individual browsers used and the name of your access provider.

By submitting your personal data and giving your consent, you agree that we collect, use and store it. We will use them exclusively for the purposes stated in the submission of consent. We will protect your personal data from misuse, unauthorized access, loss, disclosure, alteration or destruction.

Below we describe the types of personal information we collect, how we use and protect it, and how you can contact us. For the purposes of providing the services we offer, we collect, manage, process and store the following user data.

Data processing at the conclusion of the sales contract (at the time of placing the order or purchase

In the case of a purchase on our website, we will process the data necessary for identification and the conclusion, execution or cancellation of the contract. These include:

  • name and surname;
  • delivery address;
  • postal code and city;
  • country of residence;
  • e-mail address (username);
  • telephone number;
  • about payment information;
  • company name or name of the legal entity and tax number (if the user is a legal entity).

In addition to the above data, we also store cookies and other identification data that we need for implementation. We need this data to fulfill the order, i.e. to provide the delivery service and issue the invoice. We will send you an order confirmation to the e-mail address that you will provide us with at the time of purchase. Data in an anonymized summary form can be used for statistical analysis purposes.

In the case of concluding a sales contract through our website, it is necessary to pass on your payment information to payment service providers that we have authorized to process payments. We forward information about your delivery address from our side to authorized delivery partners for this purpose, to whom, in order to ensure the delivery of goods in accordance with your wishes, we forward your e-mail address and telephone number, if necessary. If necessary, he will contact you before delivery and coordinate the delivery details with you.

The basis for the collection of personal data is the contract (the basis for the submission of optional data for the realization of the contract is personal consent), since without prior fulfillment of the required data, it is not possible to realize all the rights and obligations from the contract. The condition for making a purchase is the acceptance of the General Terms and Conditions of Business and the Privacy Policy, since without the latter it is not possible to fulfill a mutual contract, as well as legal requirements in the field of online purchases.

After completing the order, the individual receives a confirmation of acceptance of the order to the e-mail address, which is forwarded to the controller when filling out the electronic purchase form.

The controller can use the data for statistical analysis in an anonymized summary form.

Submission of personal data via the contact form or any other channel

You can contact us in several ways, namely by e-mail, phone or via the contact form. When you contact us, we use the personal information that you voluntarily provide to us solely to contact you and process your request.

By submitting a comment via the online form, you provide us with your first name, last name, email address, message and, if desired, your phone number based on your consent. We will use your data to answer your question as quickly and as efficiently as possible.

Registration or creation of a user account in the online store

To provide you with the greatest possible convenience, we offer you the permanent storage of your data in a password-protected account. To create a user account we need:

  • name and surname;
  • e-mail address;
  • password in encrypted form.

The customer account is created voluntarily, and you can view and change the information at any time in your customer account. In addition, you have the option to delete your account at any time, just notify us at contact@gripnatic.com. When placing an order, the requested data must be entered to view the order in your account. When ordering products, the registered user receives a link to his email address through which the status of the ordered products can be monitored.

The basis for collecting personal data on the registration form is personal consent and a contract, since without prior registration, it is not possible to exercise all rights and obligations from the contract. The condition for registration is the acceptance of the General Terms and Conditions of Business and the Privacy Policy, since without the latter it is not possible to fulfill the mutual contract, as well as the legal requirements regarding online purchases. Treat your personal information confidentially and do not allow third parties to access it. You will remain logged in to your user account even after you leave our website, unless you actively log out.

As a result of the purchase based on registration, the controller may collect indirect data resulting from the purchase, such as:

  • home address;
  • postal code and city;
  • country;
  • phone Number;
  • payment information.

Registration for electronic newsletters or e-mail advertising

On our website, we also offer the option of signing up for e-newsletters. To reduce the possibility of fraud, we use the Google tool reCAPTCHA v3. For a successful application, we require the following information from you:

  • name and surname;
  • e-mail address.

If you sign up for email newsletters, we will use your email address to inform you about news, promotions, discounts and our events.

The basis for the collection of personal data is the personal consent of the individual who, for this purpose, provides the controller with his or her email address, which the controller uses exclusively to fulfill the individual’s request for sending e-news. By subscribing to our e-newsletters, you consent to the export, storage, and processing of data in the marketing automation tool that enables us to send e-newsletters. The output, storage, and processing of data in the marketing automation tool, which helps us continuously monitor your activities on the www.gripnatic.com page, allow us aggregated and anonymized analyzes of the use of the www.gripnatic.com website and the content on this page.

The administrator can use the individual’s data for analysis, online advertising, and content marketing. All personal data are used exclusively to perform our services, anonymized analysis, and optimize our business and are not accessible to the public, except in the case when the user expressly allows us to do so with special consent for such purposes.

In addition to signing up for electronic newsletters, the website visitor also agrees to the consent to receive personalized notifications and offers, which is valid until canceled and which includes: use of data for direct marketing, retargeting on digital advertising platforms (Meta ads and Google ads…) , with the aim of:

  • presentations of the entire Gripnatic offer,
  • export and processing of data in digital advertising tools (use of e-mail for the preparation of anonymized user segments (in this case, the e-mail cannot be attributed to a specific individual) and
  • data processing with pseudonymization (so that it cannot be attributed to a specific individual).

This consent is optional and requires the explicit consent of the user.

Commercial messages that you will receive via email will contain the following components:

  • they will be clearly and unambiguously marked as commercial;
  • the sender will be visible;
  • actions, promotions, and other marketing techniques will be marked as such, and the conditions of participation in them will also be clearly defined;
  • the method of unsubscribing from receiving advertising messages will be presented;
  • the provider will expressly respect the user’s wish not to receive advertising messages.

The right to withdraw

You can always withdraw your consent by simply clicking on the unsubscribe button at the end of each promotional email.

Logging into the Gripnatic Loyalty Club

To become a member of the club and to obtain a (online) benefit card, it is mandatory to submit the following information:

  • name and surname,
  • residential address,
  • Date of birth,
  • postcode
  • E-mail address
  • Phone Number

Indirect data resulting from the use of the club card are: mobile phone number, country of residence, gender, and data on purchases made with the membership card, such as date and value of purchase, account number, quantity of products, payment method, store of purchase, seller, tag cash registers, information about purchased products, such as product type, product EAN code, product group, product size, product color, product brand, and information about established benefits, such as purchase date and value, account number, product EAN code, product quantity, store of purchase, seller, cash register mark. Based on the processing of the said data, the member is entitled to benefits, and the manager also processes them for analysis and statistics intended for his internal business processes, especially the analysis of the success of a certain sales program and the planning of new products and services.

Participants in a prize game or promotion:

If you register for prize games organized by Gripnatic, we use the data you provided during registration to implement the cooperation agreement, mainly to inform you about the prize received and, if necessary, to advertise our offers and/or the offers of our partners in the prize game. Mandatory information for participation in any Gripnatic prize draw, which is listed in the rules of each prize draw, is (for example, but not limited to):

  • name and surname,
  • e-mail address,
  • prize delivery address,
  • data for tax assessment,
  • username on social networks.

Detailed information can be found in the relevant conditions of participation for each prize game.

Every individual who decides to participate in a prize game or promotion must provide personal information so that in the event of a win, we can notify him or her via e-mail or our Instagram account. In this case, the name and surname are published publicly. In some cases, we may also ask for additional information that we or our partners need to run a promotion, sweepstakes, or survey.

In addition, we collect:

  • other data that the user voluntarily enters in surveys;
  • other data that the user voluntarily adds subsequently in his profile;
  • communication with individual customers.

We are not responsible for the correctness, completeness, and up-to-dateness of the data entered by users.

4. Your rights based on consent given

An individual may at any time request the controller of personal data to permanently or temporarily stop the use of his data for the aforementioned purposes. You can make such a request at any time to the email address contact@gripnatic.com and specify in detail which consents you want to revoke. Cancellation is effective from the moment of cancellation.

In addition, you also have the following rights:

  • the right to access your data that has been collected in connection with it, whereby the controller may use all reasonable means to verify the identity of the individual whose personal data is, especially in the case of online services and online identifiers,
  • the right to correct inaccurate data collected in connection with it, whereby the controller may use all reasonable means to verify the identity of the individual whose personal data is, especially in the case of online services and online identifiers,
  • the right to “forget”, i.e. deletion of all data, if the conditions set out in Article 17 of the General Regulation on the Protection of Personal Data are met,
  • the right to stop using personal data for direct marketing purposes, including profiling,
  • the right to be informed about corrections, choices or restriction of processing, when the right to correction, oblivion and restriction has been exercised, unless this proves to be impossible or involves a disproportionate effort,
  • the right to transfer data from one controller to another, when the processing is based on consent or a contract, or when the processing is done by automated means,
  • the right to refuse automated decision-making, including the creation of profiles,
  • the right to report a breach of personal data protection,
  • the right to file a complaint against the controller of personal data with the supervisory authority, if he believes that the processing of his personal data violates the General Regulation on the Protection of Personal Data and legislation in the field of personal data protection.

If you want to change your personal data or want us to permanently or temporarily stop using them for the purposes for which they were provided or collected, send us an email to the email address contact@gripnatic.com or to Lipra d.o.o., Turnse 45, 1233 Dob, Slovenia. You also have the option to delete all data in your user account.

If you have exercised your right to access data from our company and after receiving a decision from our company, you believe that the personal data you received are not the personal data you requested, or that you did not receive all the requested personal data, you can before filing a complaint File a reasoned complaint with our company to the Information Commissioner within 15 days of receiving our company’s decision. Our company decides on this complaint within five working days.

5. The right to object

The individual to whom the personal data relates has the right, based on reasons related to his special situation, to object to the processing of personal data at any time, if this is based on the legitimate interests that we strive for in the company. In the company, we stop processing personal data, unless we prove imperative reasons for processing that prevail over the interests, rights, and freedoms of the individual to whom the personal data relates, or for the assertion, implementation or defense of legal claims.

Where personal data is processed for direct marketing, the individual has the right to object at any time to the processing of personal data relating to him for such marketing, including profiling if related to such direct marketing. If direct marketing is based on consent, the right to object can be exercised by withdrawing the personal consent given.

6. Individual responsibility

The user himself is also responsible for the protection of personal data, namely by ensuring the security of his username and password and the appropriate software (antivirus) protection of his computer.

7. Exceptional Disclosure

Data collected and processed by the controller will only be disclosed if such an obligation is established by law or in good faith that such action is necessary for proceedings before courts or other state authorities and for the protection and realization of its legitimate interests.

8. Consent and modification of the terms of the privacy policy

By using the website, the individual confirms that he accepts and agrees with the entire content of this privacy policy. Any changes to our privacy policy will be posted on www.gripnatic.com and will be effective only after posting on this website.

9. Cookies

When you visit the Gripnatic website, we store and read small files called cookies on your device. Cookies are invisible files that are temporarily stored on your hard drive and allow the provider to recognize your computer the next time you visit the website. We use them to make visiting our website more attractive and to enable the use of certain functions, as well as for statistical recording of page usage. Cookies do not damage your device, do not contain viruses, trojan horses or other malicious software.

Some cookies allow us to interact with each other when browsing our pages from the moment you land on them until the moment you close it – i.e. only for the duration of the browser session (so-called temporary or session cookies). With the help of temporary cookies, you can e.g. we make it possible to display the shopping cart on several pages, where you can see how many products are currently in it and how high your current purchase value is. Still other cookies remain on the device for a certain period of time and are activated with each visit to the website (so-called permanent or session cookies). Furthermore, we also use web signals (also known as “web beacons”). These are small images, usually third-party cookies or of business entities, which are stored on the hard drive of your computer and web signals are an integral part of the website.

Of course, you can set your browser so that it does not store cookies on your device. The help function in the menu bar of most web browsers explains how to prevent your browser from accepting new cookies, how to notify your browser when you receive a new cookie, or how to delete all cookies that have already been received and block all others.

Meta Ads Manager

We also use third-party retargeting technologies such as Pixels by Meta Ads Manager, formerly Facebook Ireland Limited. Retargeting allows us to target users who have already shown interest in our store and our products on our partners’ websites with online ads. For this purpose, a cookie is set, which collects data about interests under pseudonyms. Based on this information, you will be shown advertisements of our offers on the websites of our partners based on your interests. No personal data is collected directly and no user profile with personal data is linked to you.

Google Analytics

For needs-based design and continuous optimization of our pages, we use Google Analytics, a web analytics service provided by Google Inc. (hereafter Google).

The Google Analytics service uses so-called cookies, text files that are stored on your computer and enable the analysis of website usage. In this context, pseudonymized user profiles are created and cookies are used. The information generated by the cookie about your use of this website is:

  • browser type/version
  • the operating system used
  • reference URL (previously visited page)
  • the hostname of the access computer (IP address)
  • server request time

With your identification in this way, your shopping cart is not deleted and we can remember your login via a specific device and do not require re-entering your e-mail address and password. At the same time, we can store information about which version of our website to display, if several versions are available at a given moment. We also use them to determine whether you have given us your consent in accordance with this document.

An opt-out cookie is set upon arrival to prevent future collection of your data when you visit this website. An opt-out cookie is valid only in this browser and only for our website and is stored on your device. If you delete cookies in this browser, you must set the opt-out cookie again.

Google Ads

Google Ads is an online advertising program of Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, USA (“Google”), which we use for remarketing purposes. This feature allows us to present ads based on their interests to users of our website on other websites within the Google Display Network. In this purpose is to analyze user interaction on our website, e.g. which offers the user was interested in, so that after visiting our website, we can show the user targeted ads on other websites as well. For this purpose, Google stores a cookie in the browsers of users who visit certain Google services or websites in the Google display network. It is used to record the visits of these users and is used to identify the web browser on a particular computer and not to identify the person, which means that no personal data is stored.

If you do not disable the use of third-party cookies and the transfer of your data to advertising and social networks under the Privacy Settings tab and after our warning, you click on any link on our websites (outside the warning box) or click on the “I understand” button, which is an integral part warnings, it is considered that you agree to the use of said cookies and the transmission of your data to advertising and social networks. You can withdraw your consent at any time by disallowing this feature under the Privacy Settings tab.

10. Who processes your personal data and to whom do we pass it on?

All described personal data are processed by us as the controller. This means that we determine the above-defined purposes for which we collect your personal data and the methods of processing, and we are responsible for their proper implementation. In such a case, we pass your data on to our partners to ensure payments, transport and other matters related to your order. We also forward the data to our processors, who process it by our instructions.

With your consent, we can also forward the data to advertising and social networks for displaying customized ads on other websites. In addition, we also process your personal data in the tools of other business entities that we use to process personal data. Such legal entities include:

  • in relation to the processing of your order to our partners involved in the processing of the order, as set out in the section “If you make a purchase from us”:
    • about partners who operate payment systems for the provision of payments, especially in relation to payment cards:

Stripe Inc, 354 Oyster Point Blvd South San Francisco, CA 94080 United States

NLB d.d., Trg republike 2, 1520 Ljubljana, Slovenia

  • about transport partners

GENERAL LOGISTICS SYSTEMS d.o.o.

DHL Ekspres (Slovenia), d.o.o., Špruha 19, Trzin, 1236 Trzin

FedEx Express Slovenia d.o.o., Leskoškova cesta 6, Ljubljana, 1000 Ljubljana

  • about the supplier of the goods or the service center of the corresponding manufacturer in connection with the complaint of the ordered goods or service;
  • based on your consent to advertising social networks and other marketing tools that help us optimize the web and personalize content and offers:

Google HQ (registration number: 368047), based at Gordon House, Barrow Street, Dublin 4, Ireland; the company’s privacy policy is available here: https://policies.google.com/privacy?hl=en-US#intro

Meta Platforms Ireland Limited, Merrion road, Dublin, D04 X2K5, CO Dublin, Ireland; The company’s privacy policy is available here: https://www.facebook.com/privacy/policy/

  • providers of cloud computing services and other suppliers of technology and support:

One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland

  • processors of external communication, especially communication via SMS messages and chat rooms

If you believe that there has been a violation of the provisions on the protection of your personal data, please notify us at our email address contact@gripnatic.com. We will check the matter, take appropriate action and get back to you within a reasonable time. If you have any questions, concerns or comments regarding this Privacy Policy, please contact us at contact@gripnatic.com.

This personal data protection policy is valid from 18.01.2024.