Personal data protection policy

The Personal Data Protection Policy is a document containing all the information on the processing of personal data by PROFUNDUM, education, business consulting and trade, d.o.o., Vrba 18a, 4274 Žirovnica. This document provides information on the types of personal data, the purposes of processing, the legal basis, the transfer of personal data and the measures for the protection of personal data. In this document you will also find a description of your rights that you have in relation to our processing of your personal data.

The purpose of our Privacy Policy is to inform you about the privacy practices and the way in which information is collected and used on the profundum.si website. We undertake to collect, process, protect and store your personal data obtained through the use of our website and when doing business with you in accordance with the applicable European legislation (General Data Protection Regulation) and the national legislation of the Republic of Slovenia (the Personal Data Protection Act, the Electronic Communications Act, etc.) and the provisions of this Privacy Policy.

Below we will describe how and what personal data we process from website visitors and customers, whether we process this data on the basis of your consent or on another legal basis, for what purposes we use it, to whom we may disclose it and what your rights are in relation to the processing of your personal data.

Basic concepts:

Personal data means any information from which an individual can be identified (e.g. first name, last name, email address, telephone number, etc.).

Controller means the legal person who determines the purposes and means of the processing of your personal data.

Processor means a legal or natural person who processes personal data on behalf of the controller.

Processing means the collection, storage, access and any other use of personal data.

Data controller and data protection officer

PROFUNDUM d.o.o. is the controller of your personal data, which means that we are responsible for the lawful and fair processing of your personal data, which we guarantee.

Information about the controller of the personal data:

PROFUNDUM, education, business consulting and trade, d.o.o.,
Vrba 18a,
4274 Žirovnica

DŠ: SI35818816
MŠ: 8835403000

E-mail: info@profundum.si

PROFUNDUM d.o.o. has appointed a Data Protection Officer who can be contacted at dpo@jkgroup.si.

For questions regarding the Personal Data Protection Policy, please contact the Data Protection Officer at JK Group d.o.o., Stegne 27, 1000 Ljubljana, e-mail: dpo@jkgroup.si (only in case of questions, complaints or content related to the protection of personal data).

Information about individuals covered by this policy

By subscribing to the newsletter, submitting an enquiry, entering into a contractual relationship, making a purchase or otherwise signing up, you declare that you are a person of legal age and that you allow the controller to collect and process your personal data.

This Privacy Policy applies to the following categories of individuals:

Information about the personal data we process

The operator of https://profundum.si facilitates online purchases of products and events in physical and digital form (books, e-books, audio books, (online) seminars, workshops, coaching). In accordance with the purposes set out later in this policy, the controller collects the following personal data:

  • Identifying information (name and surname, address of residence);
  • contact details and details of your communication with the controller (email address, telephone number, date, time, content of postal or electronic communication, date, time, duration of telephone calls);
  • information about the customer’s purchases and invoices (date and place of purchase, products or events purchased, their quantity and price, total amount of purchase, method of payment, delivery address, invoice number and date, etc.) and information to the user in the event of cancellation of the contract, return of the product or cancellation of attendance at the event;
  • data on the user’s use of the website (date and time of visits to the website, pages visited, time spent on each page, number of pages visited, total time spent on the website, settings made on the website) and data on the use (opening, reading) of the messages received from the controller (e-mail, SMS);
  • other data voluntarily provided by the user to the controller at the time of a request for certain services, insofar as such data are necessary for the provision of the service.

We only collect your personal data if it is strictly necessary. You can visit profundum.si without providing personal data. The controller does not collect or process your personal data unless you allow or consent to it. For example, when you voluntarily provide us with information in the context of an enquiry about a specific offer or, for example, by signing up to receive a free newsletter, you are deemed to have consented to us collecting the personal data about you that you provided to us when you signed up (email address). Or, for example, if you wish to order our products or services (workshop registration, in-store purchase), you fill in a form in the shopping cart with the personal data we process for the purpose of carrying out the order.

We obtain your personal data directly from you, by making a purchase, signing up for our newsletter, making an enquiry, etc. We also obtain personal data indirectly, through your use of our website. In this case, it is information obtained through cookies and cookie-like technologies. We also only obtain this information when we have a proper legal basis and for the purposes detailed in the table below. You can find out more about which cookies we use in our Cookie Policy.

The provision of personal data is optional, except where the provision of personal data is required by law. If you choose not to provide us with personal data, there is a possibility that we may not be able to provide you with certain products and services (e.g. we may not be able to provide you with delivery of the product you have ordered if you do not provide us with a delivery address).

Information on the processing of personal data

We collect and process personal data solely for the purpose for which you have provided it to us, in accordance with the law. We do not process the personal data provided outside these purposes, but should the need arise to process personal data for an additional purpose, we will inform you in good time and in advance.

The processing of personal data in our company is always carried out on an appropriate legal basis. We may process personal data on the following legal bases:

  • Processing on the basis of a contract: We process your personal data where this is necessary for the conclusion, performance and fulfilment of contractual obligations. In this case, the provision of personal data is voluntary. If you do not provide personal data, you cannot enter into a contract with the controller, nor can the controller guarantee the supply of products to you.
  • Consent-based processing: we process your data where you have given your explicit consent. Where processing is based on consent, we will ensure that you are provided in advance with all the information you need to make your decision. You can withdraw your consent at any time. If you withdraw your consent, the controller may not be able to provide certain services to you.
  • Processing on the basis of legitimate interest: we process personal data on the basis of our legitimate interests only where the legitimate interest pursued outweighs the individual’s right to privacy. Where legitimate interest applies, the controller always carries out an assessment in accordance with the General Data Protection Regulation. In the case of processing based on legitimate interest, the user has the right to object.
  • Processing based on law: in certain cases, we are required by law to process personal data (e.g. retention of invoices for 10 years after invoicing, which is required by tax law). We process this data in accordance with the requirements of the law.

Retention of personal data

We keep the data only for as long as is necessary to fulfil the purpose for which the personal data were collected. Personal data processed by us on the basis of the law shall be kept for the period prescribed by law. Personal data processed on the basis of the individual’s personal consent shall be kept permanently or until the individual withdraws or revokes it. Before revocation, such data shall only be deleted if the purpose of the processing of the personal data has already been achieved. Personal data obtained on the basis of a contractual relationship shall be kept for the period necessary for the performance of the contract and for 5 years after termination. The purpose, basis and period of retention are set out in more detail in the table below.

Purpose of processing

Purpose of processingLegal basisTypes of personal dataStorage period
Processing of orders placed via the online shopContractual relationshipName, surname, address, delivery address, contact details (e-mail, telephone number), payment details, data subject of the orderUntil your cancellation
Processing of orders placed by telephone or e-mailContractual relationshipName, surname, address, delivery address, contact details (e-mail, telephone number), payment details, data subject of the orderUntil your cancellation
Processing enquiries, communicating with you about the provision of our products and servicesLegitimate interest in providing effective and efficient communication with potential customersContact details of the enquirer, the data contained in the enquiry (which may include date of birth, gender, metrics about the individual)Until your cancellation
Sending newslettersConsente-mail addressUntil your cancellation
Sending newsletters to customersThe lawe-mail addressUntil your cancellation
Remarketing marketing*ConsentData collected using cookiesUntil your cancellation
Carrying out statistical analyses*Legitimate interestData collected using cookies2 years
Sending a notification of an incomplete purchaseLegitimate interestName, surname, e-mail addressUntil your cancellation

The purposes marked with an asterisk are further defined in our Cookie Policy.

Transmission of your personal data

We will not disclose personal data to third parties, except to selected contractual partners, who are also bound by the General Data Protection Regulation, and we will not disclose it publicly, except by explicit consent or contract. We will disclose your personal data to third parties where this is necessary to achieve the purpose of the processing of your personal data. We have entered into a separate contractual relationship with each third party that processes your personal data on our behalf, which specifies the processing of your personal data. Third parties are also bound to respect the confidentiality of your personal data and have no right to process your personal data for any purpose outside their contractual relationship with us, nor to disclose it to unauthorised third parties.

We will share personal data with the following categories of users:

  • payment system providers such as PayPal and Stripe;
  • delivery service providers that deliver goods to you (Post Slovenije);
  • accounting services; law firms and other providers of legal advice;
  • data processing and analytics providers;
  • IT systems maintainers;
  • email providers (MailerLite and ActiveCampaign);
  • online advertising solution providers (Google, YouTube, Facebook, Instagram),
  • by public authorities where we are required to do so by law.

Security of your personal data

We implement appropriate security for all personal data we process. Your data is protected at all times against loss, destruction, unauthorised alteration and unauthorised access. We use a variety of technical and organisational measures to ensure adequate security, including:

  • limited access to personal data,
  • protecting the hardware and software where personal data is stored,
  • the security of business premises where personal data is stored; and
  • training for employees on personal data protection.

Taking care of your personal data is important to us, so we implement security measures in line with the capabilities of the technology as well as our own capabilities.

Your rights

If you have any questions about our privacy policy or the processing of your personal data, you can contact us at any time. Please contact us at info@profundum.si. Upon your request, we will provide you with the requested information or, in accordance with the legal framework, we will ensure that your rights are exercised.

You have certain rights in relation to the processing of your personal data, which are set out in more detail below:

  • Right to access and extract personal data: you have the right to request information about whether we are processing your personal data and information about the processing (types of personal data, purpose of processing, legal basis, retention period, source of the information). You can also request that we provide this data to you in a structured, machine-readable format.
  • Right to rectification of personal data: if the personal data we process about you is incorrect or incomplete, you have the right to request rectification of your personal data.
  • Right to restriction of processing of personal data: you can request that we restrict the processing of personal data; restriction of personal data is only possible in certain cases:
  1. a) if you contest the accuracy of the data for a period that allows the company to verify the accuracy of the personal data;
  2. b) the processing is unlawful and you object to the erasure of the data and instead request a restriction on its use;
  3. c) The controller no longer needs the data for the purposes of the processing, but you need the data for the establishment, exercise and defence of legal claims;
  4. d) you have raised an objection to processing, pending verification that the legitimate grounds of the company override your own;
  • Right to object to the processing of personal data: where we process your personal data on the basis of legitimate interest, you have the right to object to the processing of your personal data at any time on grounds relating to your particular situation. In such case, we will only continue to process your personal data if we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms or for the establishment, exercise or defence of legal claims.
  • Right to erasure of personal data: you can ask the company to erase your personal data without undue delay and the controller must erase the data where one of the following reasons applies:
  1. a) the data are no longer necessary for the purposes for which they were collected or otherwise processed,
  2. b) if you withdraw your consent and there is no other legal basis for the processing,
  3. c) if you object to processing and there are no overriding legitimate grounds for the processing,
  4. d) the data have been processed unlawfully,
  5. (e) the data must be erased in order to comply with legal obligations under EU law or the law of the Member State to which the controller is subject,
  6. (f) the data have been collected in connection with the provision of information society services.

However, in certain cases described in Article 17(3) of the GDPR, you do not have the right to erasure.

  • Right to withdraw consent: you have the right to withdraw the consent you have given us to process your personal data. You may withdraw your consent at any time without any negative consequences for you, but it is possible that we may not be able to provide you with certain services as a result of withdrawing your consent. You can withdraw your consent by contacting us at: info@profundum.si.
  • Right to data portability: you have the right to request to receive an extract of the personal data you have provided to us in a structured and machine-readable format and to request that we transmit it to another controller of your choice, where the processing is based on consent or on a contract and where the processing is carried out by automated means.

You can exercise your rights by contacting us at info@profundum.si.

When processing a request to exercise any of the rights listed above, we may ask you for additional personal data if we cannot reliably identify you on the basis of your request. If you do not provide us with the additional information, we will reject your request.

If you believe that the processing of your personal data has infringed the General Data Protection Regulation, you have the right to lodge a complaint with the Information Commissioner, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si.

Use of social networks and cookies

Access to social networks

Through our website, you can access the online plug-ins used by the controller in its operations: Facebook, Instagram, LinkedIn, YouTube, Vimeo.

Each social network operates in accordance with its own terms of use when providing its services, and which of these social networks processes your data and how depends on their privacy policies. The Operator accepts no liability in relation to the use of the social networks to which it provides access through its website. This is an area outside our remit, so please contact the individual social network for any questions and to exercise your rights in this regard.

The privacy policies for social networks are available at the links below:

Facebook: https://www.facebook.com/about/privacy/
Instagram: https://privacycenter.instagram.com/policy/
LinkedIn: https://www.linkedin.com/legal/privacy-policy
You Tube: https://www.youtube.com/howyoutubeworks/user-settings/privacy/

Cookies

Our website uses cookies. For information about cookies, please see our Cookie Policy.

Policy changes

We may change this Privacy Policy at any time. The most up-to-date version of the policy will always be available to you at: https://profundum.si/politika-varstva-osebnih-podatkov/.

Updated: 24.03.2025