1. DATA CONTROLLER DETAILS
Data Controller: RIDOBI s.r.o.
Legal Form: Limited Liability Company (spoločnosť s ručením obmedzeným – s.r.o.), incorporated in the Slovak Republic
Registered Office: Zichyho 1233/12, 946 57 Svätý Peter, Slovak Republic
Commercial Register: District Court Nitra (Okresný súd Nitra), Section: Sro, File No. 68961/N
Company Registration Number (IČO): 57 423 466
Tax Identification Number (DIČ): 2122713175
VAT Identification Number (IČ DPH): SK2122713175
Representative: Dóra Mihalik, Managing Director (konateľ)
E-mail: ridobisro@gmail.com
Telephone: +36 20 566 4758
Website: www.berrivit.at
The Data Controller is not required to appoint a Data Protection Officer (DPO) under the General Data Protection Regulation (GDPR). Accordingly, any enquiries regarding data protection may be directed to the Data Controller using the contact details provided above.
2. GENERAL PRINCIPLES AND LEGAL FRAMEWORK
The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and Act No. 18/2018 Coll. on the Protection of Personal Data of the Slovak Republic.
The processing of personal data is based on the following principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality.
The ordering process is carried out via an SSL-encrypted (HTTPS) connection, which prevents unauthorised persons from accessing the Customer's personal data.
3. PERSONAL DATA PROCESSED, LEGAL BASIS, PURPOSE AND RETENTION PERIOD
3.1 Website Visits (Technical Log Data)
When visiting the website, the following data are collected automatically:
IP address (anonymised in the case of Google Analytics);
date and time of the visit;
pages visited;
browser type;
operating system;
screen resolution.
Legal Basis: The data subject's consent (Article 6(1)(a) GDPR), provided through the CookieYes cookie consent platform.
Purpose of Processing: Statistical analysis and improvement of the quality and performance of the website.
Retention Period: 2 years (Google Analytics default retention setting).
Note: Statistical data are evaluated only in aggregated and anonymised form and are not linked to any identifiable individual.
3.2 Order Placement and Performance of the Contract
When an order is placed, the following personal data are processed:
full name (surname and first name);
e-mail address;
telephone number;
billing address;
delivery address (if different from the billing address);
ordered products, quantity, unit price and total purchase price;
payment method, transaction amount and transaction date;
IP address (at the time of placing the order);
any additional comments provided by the Customer (if applicable).
Legal Basis: Performance of a contract (Article 6(1)(b) GDPR); compliance with a legal obligation (Article 6(1)(c) GDPR), including accounting and tax obligations.
Purpose of Processing: Processing orders, arranging delivery, issuing invoices, and handling warranty claims.
Retention Period: 10 years from the last day of the calendar year in which the order was placed, in accordance with the mandatory retention requirements under the Slovak Accounting Act (Act No. 431/2002 Coll., Section 35) and the Slovak VAT Act (Act No. 222/2004 Coll., Section 70). Data required for handling warranty claims shall be retained until the expiry of the applicable warranty period.
3.3 Newsletter and Direct Marketing
Personal Data Processed: Surname, first name, e-mail address; optionally, areas of interest.
Legal Basis: The explicit consent of the data subject (Article 6(1)(a) GDPR).
Purpose of Processing: Sending newsletters, promotional offers, information about new products and marketing campaigns.
Retention Period: Until the consent is withdrawn. Following unsubscription, the personal data shall be permanently deleted from all relevant systems.
3.4 SMS Notifications
Personal Data Processed: Telephone number and order status.
Legal Basis: Performance of a contract (Article 6(1)(b) GDPR).
Purpose of Processing: Sending delivery and order status notifications.
Retention Period: Until the notification has been successfully delivered.
4. DATA PROCESSORS AND DATA TRANSFERS
The Data Controller engages the following data processors for the processing of personal data. A valid data processing agreement is in place with each processor to ensure that personal data are processed in compliance with the GDPR.
Payment Service Provider – Stripe
Activity: Processing of online card payments.
Registered Office: Stripe, Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA, or, within the European Economic Area, Stripe Payments Europe, Limited.
Purpose of Data Transfer: To process the Customer's online payment transactions on behalf of the Service Provider.
Hosting Provider – GoDaddy.com, LLC
Activity: Webshop hosting services.
Registered Office: 14455 North Hayden Road, Suite 219, Scottsdale, AZ 85260, USA.
Purpose of Data Transfer: Operation and hosting of the webshop.
Newsletter and CRM Provider – SalesAutoPilot Kft.
Activity: Newsletter distribution and customer relationship management (CRM).
Registered Office: 1016 Budapest, Zsolt utca 6/C, 4th Floor, Office 4, Hungary.
Company Registration Number: 01-09-286773.
Purpose of Data Transfer: Distribution of newsletters and customer relationship management.
Electronic Invoicing Provider – Doklado s.r.o.
Activity: Issuing electronic invoices (Doklado.sk system).
Registered Office: Alexandra Rudnaya 2489/40, 010 01 Žilina, Slovak Republic.
Company Registration Number (IČO): 53781856.
VAT Identification Number (IČ DPH): SK2121494078.
Commercial Register: District Court Žilina (Okresný súd Žilina), Section: Sro, File No. 77283/L.
Purpose of Data Transfer: Issuing electronic invoices.
Delivery Service – GLS General Logistics Systems
Activity: Parcel delivery services.
Registered Office: Varies by country (see the GLS website).
Purpose of Data Transfer: Delivery of the ordered parcel to the Customer's designated delivery address.
Transfers of Personal Data to Third Countries (Outside the EEA)
Stripe Inc. and GoDaddy.com, LLC are established in the United States. Transfers of personal data are carried out on the basis of the European Commission's Standard Contractual Clauses (SCCs) pursuant to Article 46(2)(c) GDPR and/or under the EU–U.S. Data Privacy Framework, where applicable.
Requests from Public Authorities
Where a court, public prosecutor, police authority, tax authority or any other competent public authority submits a lawful request, the Data Controller shall comply with its legal obligations and disclose only the minimum amount of personal data necessary for the purpose of the request, pursuant to Article 6(1)(c) GDPR.
The webshop uses cookies. Cookies are small text files stored by the Customer's web browser. For cookies requiring consent, the Data Controller uses the CookieYes service (app.cookieyes.com), which requests the Customer's consent upon their first visit to the website.
Strictly Necessary Cookies
These cookies are essential for the proper operation of the website (e.g. session cookies and shopping cart functionality). They do not require the Customer's consent.
Retention Period: Until the end of the browser session.
Statistical / Analytics Cookies
Provider: Google Analytics
Purpose: Analysing website traffic and usage.
Consent Required: Yes.
Retention Period: Up to 2 years.
Marketing / Remarketing Cookies
Providers: Google Remarketing and Facebook Remarketing.
Purpose: Delivering personalised and targeted advertisements.
Consent Required: Yes.
Retention Period: Up to 180 days.
CookieYes Cookies
Purpose: Recording and managing the Customer's cookie consent preferences.
Retention Period: 1 year.
Cookies can be managed or deleted through the settings of the Customer's web browser (including Chrome, Firefox, Safari, Edge and Opera). Please note that disabling cookies may limit the availability or functionality of certain features of the webshop.
6. PROFILING AND AUTOMATED DECISION-MAKING
The Data Controller does not carry out profiling based on Customers' behaviour, interests or other personal data and does not apply automated individual decision-making within the meaning of Article 22 of the GDPR.
7. RIGHTS OF THE DATA SUBJECT
Pursuant to Chapter III of the GDPR, data subjects may exercise the following rights. Requests may be submitted by e-mail to ridobisro@gmail.com. As a general rule, the Data Controller shall respond to requests free of charge within one month.
7.1 Right of Access (Article 15 GDPR)
The data subject has the right to obtain confirmation as to whether the Data Controller processes their personal data and, where that is the case, to receive information regarding the categories of personal data processed, the purposes of processing, the recipients of the data, the retention period and other relevant information.
7.2 Right to Rectification (Article 16 GDPR)
The data subject has the right to request the correction of inaccurate personal data concerning them and the completion of incomplete personal data.
7.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)
The data subject may request the erasure of their personal data where the data are no longer necessary for the purposes for which they were collected, where consent has been withdrawn and no other legal basis for processing exists, or where the processing has been unlawful. The right to erasure shall not apply where processing is necessary for compliance with a legal obligation, including statutory record retention requirements under Slovak accounting legislation.
7.4 Right to Restriction of Processing (Article 18 GDPR)
The data subject may request the restriction of processing where they contest the accuracy of the personal data, where the processing is unlawful but the data subject opposes erasure and requests restriction instead, or where the Data Controller no longer requires the personal data but the data subject requires them for the establishment, exercise or defence of legal claims.
7.5 Right to Data Portability (Article 20 GDPR)
Where processing is based on consent or on a contract and is carried out by automated means, the data subject has the right to receive their personal data in a structured, commonly used and machine-readable format and to transmit those data to another data controller.
7.6 Right to Object (Article 21 GDPR)
The data subject has the right to object to the processing of personal data based on the Data Controller's legitimate interests, as well as to processing for direct marketing purposes. Where the data subject objects to processing for direct marketing purposes, their personal data shall no longer be processed for such purposes.
7.7 Right to Withdraw Consent
The data subject may withdraw their consent to processing based on consent at any time, free of charge (for example, by unsubscribing from the newsletter). Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.
8. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY
The data subject has the right to lodge a complaint with a supervisory authority if they believe that the processing of their personal data infringes the provisions of the GDPR.
Competent Supervisory Authority (based on the registered office of the Data Controller):
Úrad na ochranu osobných údajov Slovenskej republiky
Hraničná 12
820 07 Bratislava 27
Slovak Republic
Website: https://dataprotection.gov.sk
Pursuant to Article 77 of the GDPR, the data subject may also lodge a complaint with the supervisory authority of their habitual place of residence. Accordingly, data subjects residing in Austria may submit a complaint to the Österreichische Datenschutzbehörde (DSB):
Barichgasse 40–42
1030 Vienna
Austria
Website: https://www.dsb.gv.at
Before contacting a supervisory authority, the Data Controller kindly requests that the data subject first contact the Data Controller at ridobisro@gmail.com so that any issue may be resolved promptly.
9. AMENDMENTS TO THIS PRIVACY POLICY
The Data Controller reserves the right to amend this Privacy Policy unilaterally. Any amended version shall become effective upon its publication on the webshop. In the event of material changes, the Data Controller shall inform data subjects either by e-mail or by publishing a notice on the website.
The data subject is responsible for providing accurate and truthful personal data. The data subject shall fully indemnify the Data Controller against any claims arising from the unauthorised provision of personal data relating to third parties.
Any matters not expressly regulated by this Privacy Policy shall be governed by the GDPR, the Slovak Act on the Protection of Personal Data, and all other applicable European Union and Slovak legislation.
Effective Date: 5 August 2026
RIDOBI s.r.o., Svätý Peter