Privacy Policy
How we handle and protect your personal data
Alpha Motors, Zoran Nedić s.p., Šalek 98, 3320 Velenje, Slovenia (hereinafter: the provider) is the controller of personal data processed through the online store www.blacklogos.com and is committed to permanently protecting all personal data of its users in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the applicable data protection legislation of the Republic of Slovenia. For any questions about personal data, contact us at info@blacklogos.si.
Privacy policy
The purpose of this privacy policy is to inform buyers, potential buyers and visitors of the websites operated by the provider about the purposes and legal bases on which the provider processes personal data.
We value your privacy, which is why your data is always carefully protected.
This privacy policy may be amended or supplemented at any time without prior notice. By using the provider’s websites after such a change, the individual confirms agreement with the amendments. Where individual cases require an additional form of consent, using the website alone does not replace it.
Our activities comply with European legislation (the GDPR and the Council of Europe conventions) and the national legislation of the Republic of Slovenia. The competent supervisory authority in Slovenia is the Information Commissioner (Informacijski pooblaščenec); as an EU resident you may also contact the data protection authority of your own country.
Personal data
Personal data is any information that identifies you as an individual: your name, surname, email or postal address, and similar.
For the purposes of its business, the provider collects the following user data:
Name, surname, street address, city, postal code, country, phone number and email address. If you want an invoice issued to a company, we also need the company name, VAT number, registered office and whether the company is a VAT payer. Card payments are entered directly with the payment provider; the provider never sees or stores full card numbers.
We also process any other data you enter into the relevant forms on the website (e.g. the contact form or newsletter signup).
By placing an order on the website you agree that the provider may process the personal data you have voluntarily provided (name and surname, address, email address and any other data provided for the purpose of fulfilling the contract) for the purposes of negotiating, concluding and performing the contract — your order.
The provider collects and processes your personal data on the following legal bases:
- law and contractual relationships,
- legitimate interest,
- consent (e.g. newsletter, marketing cookies).
Processing based on law and contractual relationships
Where the provision of personal data is a contractual obligation, an obligation necessary for the conclusion and performance of a contract with the provider, or a legal obligation, you must provide the personal data; without it, the provider cannot conclude the contract or deliver the products, as it lacks the data needed to perform the contract. This includes fulfilling your orders (delivering products and providing services), communicating with you, verifying your payments and fulfilling the other obligations of the provider and/or your obligations (Article 6(1)(b) GDPR).
Processing based on legitimate interest
The provider may also process data on the basis of a legitimate interest it pursues, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data. Where legitimate interest is relied on, the provider always carries out an assessment in accordance with the GDPR.
Purpose of processing
The provider processes your personal data solely for the fulfilment of your order and, where you have given consent, for the purposes covered by that consent (e.g. sending the newsletter).
Contractual processing of personal data
As an individual you are informed and agree that the provider may entrust individual tasks related to your data to other persons — contractual processors. Contractual processors may process the entrusted data exclusively on behalf of the provider, within the limits of the provider’s authorisation (in a written contract or other legal act) and in accordance with the purposes defined in this privacy policy.
The contractual processors the provider works with are:
- the accounting service VIZIJA Računovodstvo d.o.o.,
- payment service providers (Stripe, PayPal),
- postal and delivery services (Pošta Slovenije and partner carriers),
- the email delivery service used for transactional emails,
- the developer and maintainer of the online store.
The provider will not pass your personal data to unauthorised third parties. Contractual processors may process personal data only within the controller’s instructions and may not use it to pursue any interests of their own. The controller and the users of the data do not transfer personal data to third countries outside the EU/EEA, except where a processor (e.g. a payment provider) ensures appropriate safeguards under Chapter V of the GDPR.
Retention of personal data
The provider will store your personal data only for as long as necessary to achieve the purpose for which it was collected and further processed. Data processed on the basis of law is stored for the period prescribed by law (e.g. invoices under tax legislation). Data processed for the performance of a contract is stored for the period necessary for the performance of the contract and for 5 years after its termination, except in the event of a dispute between you and the provider, in which case the data is stored for 5 years after a final court or arbitration decision or settlement, or, if there was no court dispute, 5 years from the amicable resolution.
Data processed on the basis of your consent or the provider’s legitimate interest is stored until the consent is withdrawn or processing is objected to. Such data is deleted before withdrawal only when the purpose of the processing has already been achieved or where required by law.
After the retention period expires, the controller effectively and permanently deletes the personal data so that it can no longer be linked to a specific individual.
Freedom of choice
You control the information you provide about yourself. If you decide not to provide your data to the provider, you will not be able to access certain parts or functions of the website. If your personal data changes (postal code, email, physical address, phone number), please inform us of the changes at info@blacklogos.si.
Security
All information provided is protected against access by third parties. Your data is protected at all times against loss, destruction, forgery, manipulation and unauthorised access or disclosure. The provider uses appropriate technical and organisational measures and information mechanisms that ensure the undisturbed operation of the website and the security of the data transferred on it.
Minors
The provider strongly recommends that all parents and guardians teach their children safe and responsible handling of personal data on the internet. Minors should not transmit any personal data to websites without the permission of their parents or guardians. The provider will never knowingly collect personal data from persons it knows to be minors.
Your rights regarding data processing
In connection with your personal data you have a number of rights: the right to be informed, the rights of access, rectification, erasure, restriction of processing, data portability, objection, and the right to lodge a complaint.
Right to be informed: the right to know what data we collect about you, for what purposes and for how long, where we obtain it, to whom we disclose it, who processes it besides us and what other rights you have in relation to the processing. All of this is described in this privacy policy; if you have further questions, write to info@blacklogos.si.
Right to withdraw consent: where you have consented to the processing of your personal data (for one or more specific purposes), you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal. Consent can be withdrawn by a written statement sent to info@blacklogos.si. Withdrawing consent has no negative consequences, but the provider may no longer be able to offer you certain services that cannot be provided without personal data.
Right of access: you have the right to obtain from the provider confirmation as to whether personal data concerning you is being processed and, where that is the case, access to that data and the information listed in Article 15 GDPR (purposes of processing, categories of data, recipients, retention periods or criteria, existence of your other rights, source of the data, existence of automated decision-making).
Right to rectification: you have the right to obtain without undue delay the rectification of inaccurate personal data concerning you and, taking into account the purposes of processing, the completion of incomplete data.
Right to erasure: you have the right to obtain the erasure of personal data concerning you without undue delay where one of the following applies: the data is no longer necessary for the purposes for which it was collected; you withdraw consent and there is no other legal basis; you object to the processing and there are no overriding legitimate grounds; the data has been processed unlawfully; the data must be erased to comply with a legal obligation under EU or Member State law. In certain cases described in Article 17(3) GDPR the right to erasure does not apply.
Right to restriction of processing:you have the right to obtain restriction of processing where: you contest the accuracy of the data (for the period needed to verify it); the processing is unlawful and you oppose erasure and request restriction instead; the provider no longer needs the data but you require it for legal claims; or you have objected to processing, pending verification of whether the provider’s legitimate grounds override yours.
Right to data portability: you have the right to receive the personal data concerning you which you have provided to the provider in a structured, commonly used and machine-readable format and to transmit it to another controller, where the processing is based on consent or a contract and is carried out by automated means. Where technically feasible, you may request direct transmission from one controller to another.
Right to object: on grounds relating to your particular situation, you may object at any time to processing based on legitimate interest (Article 6(1)(f) GDPR), including profiling; the provider will stop processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or grounds for legal claims. Where personal data is processed for direct marketing, you may object at any time and the data will no longer be processed for that purpose.
Right to lodge a complaint with a supervisory authority: without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the EU country of your habitual residence, place of work or the place of the alleged infringement (in Slovenia this is the Information Commissioner), if you consider that the processing of your personal data infringes data protection rules.
All requests concerning the exercise of rights in relation to personal data can be addressed, in written form, to the controller at info@blacklogos.si.
For the purposes of reliable identification the controller may request additional data from you and may refuse to act only if it can demonstrate that it cannot reliably identify you. The controller must respond to your request without undue delay and at the latest within one month of receiving it.
In the event of a personal data breach, the provider is obliged to notify the competent supervisory authority, except when the breach is unlikely to endanger the rights and freedoms of individuals. Where a breach is likely to result in a high risk to your rights and freedoms, the provider will notify you without undue delay, in clear and plain language.
Cookies
Cookies are text files that the web server places on your device. Cookies used on this site do not contain data that could reveal your identity on their own; they help the site recognise a returning visitor and adapt to them.
You can find out more on the Cookie policy page.
Facebook and Instagram plugins
On our social media accounts, such as Facebook and Instagram, you can contact us directly via the comment, messaging and chat functions. The information you send us this way is processed exclusively for the purpose of handling your comment, request or question.
On the basis of legitimate interest we are entitled to manage our social media accounts and the content we share on them, engage with visitors and respond to your requests.
In addition, our websites may use Facebook and Instagram plugins. When you visit our website, the plugin establishes a direct connection between your browser and the Facebook/Instagram servers, and data may be transmitted directly from your device to the operator of the social network. We have no influence over the data collected by the plugin. If you are logged in to these networks, your use of the service can be linked to your account; interactions with the plugins (likes, follows, shares, comments) may be shown in your profile. Even if you are not logged in, the plugins may send your IP address to the social network operators. Please bear this in mind when using our services.
We explicitly point out that we have no influence over the scope, nature and purpose of the processing carried out by the social network provider, and refer you to their privacy policies:
- Facebook: https://www.facebook.com/about/privacy/
- Instagram: https://help.instagram.com/519522125107875/
Publication of changes
Any change to our personal data protection policy will be published on this website.
By using the website the individual confirms that they accept and agree with the entire content of this privacy policy.
