Privacy Policy

We collect, use, process and share your personal data in accordance with privacy, data protection, and information security laws to make sure your data protection and privacy rights are implemented, protected and enforceable.

We integrate various legal, technical and organizational solutions to comply with applicable laws on personal data, privacy, and security protection in countries where we operate, provide services or deliver goods. This Privacy Policy sets forth the basic rules and principles by which we process your personal data, and mentions our responsibilities while processing your personal data. We do not process personal data of children and our services and goods are targeted to consumers above 16 (sixteen) years old.

The Privacy Policy is a basic document as a transparency obligation to provide information where personal data are collected and processed from you or third parties. To receive a more detailed review of our specific measures with regard to the processing of your personal data, please contact us via our contact information.

Contact information:
PROMENADA INT., d.o.o.
Address: Polica 149, 1290 Grosuplje, Slovenia
Email: contact@ninavidmar.com

1. Terms we use as legal bases of the processing

Any processing of personal data must have a legal basis and we count on them to process your personal data. We use the main three bases to process your personal data: consent, contract, and legitimate interests.
Consent – the legal basis for the processing of your personal data which constitutes your clear and freely given agreement to the processing of your personal data for a specific purpose.
Contract – the legal basis for the processing of your personal data necessary for us to perform a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
Legitimate Interests – the legal basis for the processing of your personal data when it is necessary for us to do business provided those interests are not outweighed by your rights and interests and those interests have a specific purpose, they are necessary, and they are balanced.
There are three other possible legal bases defined in laws and when they are applicable we will count on them.

2. Consent rule and interrelation with other legal grounds

If you have given consent to the processing of your personal data, you can freely withdraw such consent at any time by contacting us or using specific buttons to unsubscribe from some processing.
If you do withdraw your consent, and if we do not have or use another legal basis for the processing of your data, then we will stop the processing of the personal data and may delete in specific situations, including in case if you request the deletion of your personal data and we are obliged to delete.
If we have another legal basis for the processing of your data (for example, it may be required by the applicable law), then we may continue to do so which is subject to our legal interests and rights.

3. Our responsibilities

When we process your personal data, we have legal obligations to comply with some laws. There are two roles that impose different legal obligations on us.
Mainly, we act as a data controller when we determine the purposes and means of the processing of your personal data and we are responsible for the implementation of the data processing principles, legal bases for processing, data subject rights, privacy by design and by default, record keeping, cooperation with local data protection authority, information security safeguards, data breach notifications, prior consultations, transfers and so on.
We may under specific circumstances act as a data processor when we process personal data on behalf of another controller and we are responsible for following controller’s instructions, record keeping, cooperation with local data protection authority, information security safeguards, data breach notifications, transfers and so on.

4. Recommendations for you

You should read this Privacy Policy carefully. We want to make sure that you understand all your rights. It is important for both of us that you maintain your personal data confidential and secure.
If you provide us with personal data about other individuals, we will only employ that data for the special reason for which it was provided to us. By sending the data, you shall be sure that you have the right to dispose to process the personal data on your behalf in accordance with this Privacy Policy. In case if you submit a third party’s personal data, be sure that you have a legal basis for the processing of such data.
According to the applicable laws, you may become a data controller/processor under specific circumstances and it will impose additional obligations on you.

5. Processed data

We process personal data when you interact with or order something on our website https://www.bloomdegemme.com (the “Website”), especially:
– you browse any page of the Website;
– you order and purchase the goods;
– you choose delivery options;
– you subscribe to our newsletters/updates;
– you fill out contact forms, sign up forms, welcome discount forms, referral program forms, and other forms;
– you participate in social media competitions;
– you leave a review and rate the goods;
– you communicate with us;
– you use our services;
– you receive notification from us;
– we measure the Website’s traffic;
– in cases that do not depend on you but we have a legal basis to collect such data.
We collect the following types of data:
– name;
– age;
– video and images;
– address;
– email;
– banking details;
– purchasing history;
– online browsing history;
– data that identifies such as your IP address, login information, browser type, and version, time zone setting, browser plug-in types, some location information about where you might be, operating system and version;
– data on the use of the Website such as URL clickstreams (the path taken through the Website), page response times, download errors, and other actions;
– other personal data you share with us or personal data that we may legally obtain for our legitimate interests.
The recipients of the collected data are the highest management level or authorised personnel of our company.

6. Purposes and legal basis for the processing

We process the data for:
– Accepting payments and delivery of goods. We need to confirm your payment and we have to know where to deliver ordered goods. Legal basis: Contract.
– Providing services. We need to provide services accessible via the Website. Legal basis: Legitimate Interests.
– Providing newsletters/offers/updates which may be interesting to you. Legal basis: Consent; Legitimate Interests.
– Keeping the Website running (managing your requests, remembering your settings, hosting and back-end infrastructure). Legal basis: Legitimate Interests.
– Preventing frauds, illegal activity or any violation of the terms or Privacy Policy. We may disable access to the Website, erase or correct personal data in some cases. Legal basis: Legitimate Interests.
– Improving the Website (testing features, interacting with feedback platforms, managing landing pages, heat mapping the Website, traffic optimization, and data analysis and research, including profiling and the use of machine learning and other techniques over your data and in some cases using third parties to do this). Legal basis: Legitimate Interests.
– Customer support (notifying you of any changes to the Website, services, solving issues, any bug fixing). Legal basis: Contract; Legitimate Interests.

7. Your rights as data subject

You may ask us to refrain from using your data for marketing (when you opted-in). You can opt-out from marketing by contacting via the contact form or pressing a specific button (“unsubscribe”).
You can exercise the following rights by contacting us via the contact information.
You have the right to access information about you, especially:
– the categories of personal data;
– the purposes of data processing;
– third parties to whom the data disclosed;
– how long the data will be retained and the criteria used to determine that period;
– other rights regarding the use of your data.
You have the right to make us correct any inaccurate personal data about you.
You can object to using your personal data for profiling you or making automated decisions about you. We may use your data to determine whether we should let you know information that might be relevant to you (for example, tailoring emails to you based on your behavior).
You have the right to the data portability of your data to another service or website. We will give you a copy of your data in a readable format so that you can provide it to another service. If you ask us and it is technically possible, we will directly transfer the data to the other service for you.
You have the right to be “forgotten”. You may ask erasing any personal data about you if it is no longer necessary for us to store the data for purposes of your use of the Website.
You have the right to lodge a complaint regarding the use of your data by us. You can address a complaint to your national regulator.
In the context of the right to access information, we shall provide you with the information within one month of your request unless there is a justified requirement to provide such information faster. This term may be extended according to the applicable law.
Under some circumstances, we may decline your request or we may require your identification documents to define whether you are who you are to avoid any unlawful disclosure of your personal data.

8. Security

We have security and organizational measures and procedures to secure the data collected and stored. The Website uses a protected mode of communication via SSL (Secure Socket Layer) which allows the encoding of your connection on the Internet. You acknowledge that no data transmission is guaranteed to be 100% secure and there may be risks. You are responsible for your login information and password. You shall keep them confidential.
In case if your privacy has been breached, please contact us immediately. When the breach is likely to result in a high risk to your rights and freedoms, we will communicate the breach to you without undue delay.

9. Location of the processing of personal data and third-party service providers

The personal data is collected and processed by our company incorporated in Slovenia.
The Website contains links to third-party sites. The Privacy Policy does not cover the privacy practices of such third parties. These third parties have their own privacy policies and we do not accept any responsibility or liability for their sites, features or policies. Please read their privacy policies before you submit any data to them.
There are the following third parties:
– email service providers to notify you and for direct marketing purposes;
– delivery partners to deliver ordered goods;
– services for operating processes;
– website analytics companies to analyze data and improve our services and the Website;
– advertising companies for marketing purposes;
– social media companies to promote and be present in social media.

10. Retention policy

We store personal data as long as we need it and the retention practice depends on the type of data we collect, regulatory burden, and how we use the personal data. The retention period is based on criteria that include legally mandated retention periods, pending or potential litigation, intellectual property or ownership rights, contract requirements, operational directives or needs, and historical archiving.

11. California privacy

The California Consumer Privacy Act (“CCPA”) provides Californian residents with specific rights regarding their personal data. When the CCPA is applicable, you may request to disclose some data to you about our collection and use of your personal data over the past 12 (twelve) months. You may ask us to delete personal data collected from you unless there are exceptions. If we sell personal data, you may opt-out of that sale.
We may not discriminate against you for exercising a CCPA right and if you choose to enforce applicable CCPA rights, we shall not charge you different prices or provide you a different quality of the services.

12. Cookie policy

The Website uses cookies or similar technology to collect information about your access to and use of the Website. Cookies are pieces of information that include a unique reference code that we transfer to your device to store and sometimes track information about you.
A few of the cookies we use last only for the duration of your web session and expire when you close your browser. Other cookies are used to remember you when you return to the Website and will last for longer.
Most browsers automatically accept cookies but, if you prefer, you can change your browser to prevent that. You can prevent the setting of cookies by adjusting the settings on your browser. Alternatively, you may wish to visit https://aboutcookies.org, which contains comprehensive information on how to do this on a wide variety of browsers. Please note, however, that by blocking or deleting cookies you may not be able to take full advantage of the Website.
Our cookies will be used for essential (necessary) reasons, statistics, and marketing. Only necessary cookies are automatically installed. Other cookies may be accepted or rejected by you.

The list of cookies we are using:

Cookie Source Type Expiry
cookielawinfo-checkbox-necessary
Purpose: Determines whether the visitor has accepted the cookie consent box.
Website Essential/ necessary 1 day
cookielawinfo-checkbox-non-necessary
Purpose: Determines whether the visitor has accepted the cookie consent box.
Website Essential/ necessary 1 day
PHPSESSID
Purpose: Preserves user session state across page requests.
Website Essential/ necessary Session
_ga
Purpose: Registers a unique ID that is used to generate statistical data on how the visitor uses the Website.
Google Analytics Statistics 2 yeas
_gat
Purpose: Used by Google Analytics to throttle request rate
Google Analytics Statistics 1 day
_gid
Purpose: Registers a unique ID that is used to generate statistical data on how the visitor uses the Website.
Google Analytics Statistics 1 day
collect
Purpose: Used to send data to Google Analytics about the visitor’s device and behavior. It tracks the visitor across devices and marketing channels.
Google Analytics Statistics Session
r/collect
Purpose: Used to send data to Google Analytics about the visitor’s device and behavior. It tracks the visitor across devices and marketing channels.
doubleclick.net Marketing Session
yith_wcwl_session_
Purpose: For website admin functions.
Website Essential/ necessary 29 days

Contact information

If you still have any question or need clarification with regard to our privacy processes and practice, please contact us:

PROMENADA INT., d.o.o.
Address: Polica 149, 1290 Grosuplje, Slovenia
Email: contact@ninavidmar.com