DATA PROTECTION AND COOKIES
The purpose of the Privacy Notice (“Notice”) is to inform you of what personal information we collect and for what purposes, what we do with it, how we take care of its security, and what your rights are that you can exercise in regarding the processing of personal data. We take the protection of your personal data extremely seriously and responsibly. We fully respect our obligations regarding the lawful, fair, and transparent processing of personal data. We advise you to familiarise yourself in detail with the content of this Notice.
To ensure that this Notice complies with personal data protection regulations, PharmaHemp reserves the right to amend or supplement it. We will inform you about the changes on time in the most appropriate way, e.g. via email or by posting on the website.
Company address: Koprska 106c, SI-1000 Ljubljana
Address of the business unit: Cesta v Gorice 8, SI-1000 Ljubljana
VAT ID: SI 11032413
Registration number: 2343428000
Phone: +386 1 423 97 90
What personal data do we process?
a.) Basic contact information (name, surname, telephone number, e-mail address, address, city, town, street, country);
b.) Information on the use of our websites (clicks on links, time spent) and information on the response to our e-mails (whether the message was opened, which links you clicked on);
c.) Information we need to fulfil the contract and deliver the purchased goods (the subject of purchase, price, delivery address, delivery time, method of payment, date of payment, data on complaints, information on the issued invoice, etc.)
d.) Server information (e.g., date and time of visits, subpages visited, the information you viewed or searched for, etc.).
e.) Device information (information about the computer or mobile device with which you access the website, including the operating system, model, web browser, etc.).
f.) Information about the use of our website.
g.) Aggregate data for the purposes of advertising and marketing, such as viewed and purchased items as well as other activities connected to the purchasing process.
Legal basis for the processing of personal data
We only collect your personal data when it is necessary or you have consented to it yourself. We will not process your personal data if the purpose or basis for their processing is not adequately substantiated by the applicable regulations in the field of personal data protection (Personal Data Protection Act, Official Gazette of the Republic of Slovenia No. 94/07 – official consolidated text (ZVOP-1)). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals concerning the processing of personal data and the free movement of such data (GDPR) and the Electronic Communications Act, Uradni list RS 109/12, 110/13, 40/14 – ZIN-B, 54/14 – exc. US, 81/15, and 40/17 (ZEKom-1)).
PharmaHemp will process your personal data on the following legal grounds:
By visiting our website, you have accepted and agreed to the General Terms and Conditions of Use of this website and have entered into a contract with PharmaHemp, which is used as the legal basis for the processing of your personal data. The data is encrypted and transferred to the server in a secure format. Such a system prevents anyone from intercepting your personal information.
PharmaHemp also processes your personal data based on a legal basis:
based on national legislation, including the Prevention of Money Laundering and Terrorist Financing Act (Official Gazette of the Republic of Slovenia, Nos. 68/16 and 81/19; ZPPDFT-1), the Personal Data Protection Act (Official Gazette of the Republic of Slovenia, No. 94/07 – officially consolidated text; ZVOP-1), Copyright and Related Rights Act (Official Gazette of the Republic of Slovenia, No. 16/07 – officially consolidated text, 68/08, 110/13, 56/15 and 63/16 – ZKUASP; ZASP), etc., under other international treaties and EU regulations, which oblige PharmaHemp to provide personal data of individuals in certain cases to state authorities and other controllers to fulfil their or their legal obligations or responsibilities.
PharmaHemp may process personal data based on a legitimate interest, e.g.:
a.) for statistical purposes and to collect demographic data and the interests of visitors,
b.) to identify problems with the server and the website,
c.) to conduct business analyses,
d.) for further development of the offer,
e.) to improve or adapt services to the individual,
f.) to determine the effectiveness of promotional activities and advertising,
g.) based on other legitimate interests.
In certain cases, PharmaHemp may process your personal data based on your personal consent to carry out marketing activities, such as sending current news and general information about offers, news, benefits, events, or prize games, and to inform about the offer of services tailored to your personal interests. based on the profiling used by PharmaHemp for these purposes. Personal consent is completely voluntary and is not a condition for concluding a contract. In these cases, the processing takes place within the framework of a statement of the given purpose and agreed methods of notification, until the withdrawal of consent.
Purposes of personal data processing
We may use your personal information for one or more of the following purposes:
a.) communicating with you regarding the provision of our services and responding to your inquiries;
b.) the conclusion of the contract and the fulfilment of obligations arising from the concluded contract;
c.) marketing communication (sending e-mails and SMS messages);
d.) to assert any legal claims and resolve disputes;
e.) for statistical analyses on the sale of our goods and the use of our websites;
f.) marketing and advertising on third-party websites
How long do we keep your personal information and what happens to it then?
The period of retention of personal data depends on the basis and purpose of processing each category of personal data. Personal data are stored only for as long as it is prescribed or allowed and necessary to achieve the purpose for which they were collected or further processed. After fulfilling the purpose, we will keep only the personal data that we are obliged to keep under the law or that we might need for evidentiary or defensive purposes if there was a possibility of making legal claims. Other data shall be deleted, destroyed, blocked or anonymised, unless otherwise provided by law for individual types of personal data.
We keep your personal data, which we process to send offers and notify you of news, until your cancellation, or in any case for a maximum of five years from the date of consent. After this period, we will ask you for your consent again.
Data on issued invoices are kept for 10 years from the date of issue.
After the retention period, personal data are effectively deleted or anonymized, which means that we process them in such a way that it is no longer possible to link it to you or attribute it to you.
The voluntary transmission of data and the consequences of non – transmission
The provision of personal data is voluntary. You are not obliged to provide us with personal data, but if you do not provide them, you cannot enter into a contract with us (as we need them to deliver the order). We will state which data is such that its transmission will have the stated consequences each time we obtain personal data from you.
Who has access to the personal information that you have provided to us? Will we disclose your personal data to third parties or transfer it outside the EU?
We take your privacy very seriously. Your personal information is a trade secret of PharmaHemp. PharmaHemp employees process your personal information under our credentials and our internal policies. Contractual processors are committed to protecting confidential information and respecting the rights of individuals in the same way as PharmaHemp employees.
We do not pass on your personal data and do not provide access to it to third parties other than those who have a written contract with us, based on which they perform certain tasks related to data processing and are obliged to comply with legislation on processing and protection of personal data. contractual processors. Contractual processors to whom we provide personal data are, for example:
a.) marketing service providers;
b.) providers of electronic mail;
c.) software solution providers;
d.) delivery services, etc.
Contractual processors may only process personal data under our instructions and may not process personal data for their purposes. They are committed, together with their employees, to protecting the confidentiality of your personal information.
What are your rights regarding the processing of personal data?
You may at any time request access to or access to your personal data, their correction or deletion, restrict their processing or object to the processing. We will notify you if this request will affect the ability of this website to continue to operate. In certain cases, you also have the right to transfer your personal data to another controller. The latter depends on the technical capabilities and internal policies of each operator.
Consent to the processing of personal data for the submission of tenders and notification of news may be revoked at any time, provided that the revocation of consent does not affect the lawfulness of the processing of personal data based on this consent for the period before revocation.
PharmaHemp assumes no responsibility for the authenticity, accuracy, and timeliness of the personal information you provide. The user is obliged to take care of the accuracy and up-to-dateness of all submitted data.
In the event of a breach of personal data protection, we will notify you under the conditions set by applicable law.
Procedure for exercising rights
You can address your requests regarding the exercise of personal data rights in writing to any contact listed at the top of this document under Personal Data Controller and Contact Data.
For reliable identification in the case of exercising rights concerning personal data, we may request additional information from you, and we may refuse to take action only if we prove that we cannot reliably identify you.
We must respond to your request to exercise your personal data rights without undue delay and at the latest within one month of receiving your request.
The right to appeal
You can complain about the processing of personal data with the supervisory body of Slovenia, i.e. the Information Commissioner, at any time, with the address Dunajska 22, 1000 Ljubljana.
Exclusion of liability
PharmaHemp shall not be liable for any damages incurred by you for providing incorrect, false, incomplete, or out-of-date information to your provider.
The same applies to PharmaHemp’s liability if the damage is caused by any reason on your part, e.g. that someone has made an unauthorised purchase of goods on your behalf by gaining access to the means to access the online store (e.g. passwords, computer, telephone…) for no reason on the part of the company. You are solely responsible for protecting the information required to access the online store.
You are obliged to inform us immediately of any suspicion of misuse of your personal data or data necessary to access certain parts of the website (username and password) or in case of unauthorised access to this data.
When a contractual relationship is established between the provider and the user, in any case regarding the exclusions and limitations of the provider’s liability, the provisions governing this relationship (contract, general conditions, etc.) apply.
What are cookies?
A cookie is a small text file that is transferred to a user’s computer when they visit the website and usually contains the name of the server from which the cookie was sent, the lifetime of the cookie, its value – a randomly generated unique number.
The cookie itself does not contain or collect information. However, if it is read by the server together with a web browser, this can help the site to perform more user-friendly services, e.g. to remember your username and password for future registration or to remember previous purchases or user account information. Only the server that sent the cookie can read and use this cookie. On a trusted website, cookies can enrich the experience. However, cookies can also be used in ways that constitute an invasion of an individual’s privacy. Cookies are not harmful and are always time-limited.
The purpose of cookies
The purpose of cookies is to improve the performance of the website and the user experience when viewing websites. The interaction between you and the website is faster and easier with cookies. With their help, the site remembers your personal preferences and experiences. This saves time and makes browsing the web more efficient.
Some of the cookies we use are temporary, and some are stored on your device for a certain period, even after you have already left our website. We use temporary cookies to measure the number of website visitors, which enables us to check the effectiveness of the display of content and the relevance of advertisements, as well as the continuous improvement of websites. With stored cookies, we store contact information for later visits to the website, so that the next time you no longer have to log in or the online display of content is adapted to your device. We also use stored cookies that originate from other websites, e.g. Facebook, Twitter, Google, and others. If you do not agree with their use, cookies will not be installed.
We collect data collected through cookies exclusively for statistical purposes and to collect demographic data and visitor interests (but only in such a way that your identity cannot be discovered), for identifying server problems, editing websites, and informing about products. tracking the user through various websites, adapting the content to their interests, and for marketing and advertising purposes.
In addition to this Notice, we advise you to read the General Terms and Conditions of Use, which are published on the website, and together with this Notice form a binding contract between you and PharmaHemp.