Privacy Policy
Last updated: August 2, 2024
- 1. Introduction & Data Controller
- 2. What Personal Data We Collect
- 3. How We Use Your Data
- 4. Legal Basis for Processing
- 5. Sharing Data with Third Parties
- 6. International Data Transfers
- 7. Data Retention
- 8. Your Rights Under GDPR
- 9. How to Exercise Your Rights
- 10. Cookie Usage
- 11. Children's Privacy
- 12. Changes to This Policy
- 13. Supervisory Authority & Complaints
- 14. Contact the Data Controller
1. Introduction & Data Controller
This Privacy Policy applies to all personal data collected and processed by AuraTech Global Store in connection with the operation of our e-commerce website and provision of our services.
The Data Controller — the entity responsible for deciding how and why your personal data is processed — is:
Data Controller: [YOUR_COMPANY_NAME]
Legal Form: Sole Trader (s.p.) — Republic of Slovenia, EU
Address: [YOUR_ADDRESS_SLOVENIA]
VAT / Tax Number: [YOUR_VAT_NUMBER]
Privacy Contact Email: support@auratech.store
This policy complies with the EU General Data Protection Regulation (GDPR) 2016/679 and Slovenian data protection law (ZVOP-2). By using our website or making a purchase, you acknowledge this Privacy Policy.
2. What Personal Data We Collect
We collect only the personal data necessary to provide our services. The categories of data we may collect include:
2.1 Data You Provide Directly
- Identity data: First name, last name
- Contact data: Email address, phone number (optional)
- Delivery data: Shipping address (street, city, postal code, country)
- Payment data: Payment method type (e.g., PayPal, Visa). Note: we do not store full card numbers — these are handled exclusively by PayPal
- Account data: Username and account preferences (if you create an account)
- Communications data: Messages you send to our support team (email content, subject, timestamps)
2.2 Data Collected Automatically
- Technical data: IP address, browser type and version, operating system, device type
- Usage data: Pages viewed, time spent on pages, links clicked, referring URLs
- Transaction data: Products ordered, order amounts, order dates, order history
- Cookie data: Session identifiers, preference settings, analytics identifiers (see our Cookie Policy)
2.3 Data We Do NOT Collect
- Full credit or debit card numbers (handled exclusively by PayPal)
- Government-issued ID numbers or passport data
- Sensitive personal data (racial/ethnic origin, health data, biometric data, political opinions, religion)
- Personal data of children under 16 years of age (see Section 11)
3. How We Use Your Data
We use your personal data only for the purposes described below, and only to the extent necessary:
- Order Processing & Fulfilment: To process your orders, arrange payment, coordinate shipping, and manage delivery. This includes communicating order status, shipping updates, and tracking information
- Customer Support: To respond to your enquiries, complaints, return requests, and warranty claims
- Account Management: To create and maintain your account, manage your preferences, and provide a personalized shopping experience
- Transactional Emails: To send order confirmations, dispatch notifications, refund confirmations, and essential account communications. These are not marketing emails
- Marketing Emails: To send promotional offers, new product updates, and discount codes — only if you have explicitly opted in to marketing communications. You may unsubscribe at any time
- Analytics & Website Improvement: To understand how users interact with our website, identify technical issues, and improve the shopping experience. Analytics data is aggregated and anonymized where possible
- Fraud Prevention & Legal Compliance: To detect, prevent, and investigate fraud, unauthorized transactions, or other illegal activity. To comply with applicable laws, regulations, and legal obligations
- Financial Record-Keeping: To maintain accurate financial records as required by Slovenian accounting law and EU VAT regulations
We will never use your data for purposes incompatible with those stated here without seeking your consent first.
4. Legal Basis for Processing (GDPR Art. 6)
Under the GDPR, we must have a lawful basis for each type of processing. The following legal bases apply:
- Contract performance (Art. 6(1)(b)): Processing your name, address, email, and payment information is necessary to fulfil your purchase contract — to process your order, arrange delivery, and handle returns. Without this data, we cannot provide our service.
- Legitimate interests (Art. 6(1)(f)): We may process usage data and technical data for fraud prevention, security purposes, and improving our website. We have assessed these interests and determined they do not override your rights and freedoms.
- Consent (Art. 6(1)(a)): For non-essential cookies and marketing communications, we rely on your freely given, specific, and informed consent. You may withdraw consent at any time (see Section 9).
- Legal obligation (Art. 6(1)(c)): We are required to retain certain financial and transactional records to comply with Slovenian accounting law, EU VAT regulations, and other legal obligations (typically 7 years).
5. Data Sharing with Third Parties
We share your personal data only with the following trusted third-party service providers, strictly to deliver our services:
- PayPal (Netherlands B.V.): Payment processing. Your payment details are processed directly by PayPal under their Privacy Policy. We share your name and order amount as required to process payment.
- Google / Firebase: We may use Firebase for user authentication and/or database services. Google processes data in accordance with the Google Cloud Privacy Notice.
- Shipping & Fulfilment Providers: We share your name and delivery address with our shipping partners (e.g., postal services, courier companies) to arrange delivery of your order.
- Email Service Providers: To send transactional and marketing emails on our behalf. These providers process only the data necessary to deliver emails (email address, name).
- Analytics Providers: For aggregated, anonymized website analytics to understand user behavior (e.g., Google Analytics, if used). Analytics data does not identify you personally.
- Legal and Regulatory Bodies: We may disclose data if required by applicable law, court order, or governmental authority (e.g., tax authorities, law enforcement).
All third-party processors are bound by written data processing agreements (DPAs) that require them to process your data only according to our instructions and in compliance with GDPR.
6. International Data Transfers
Some of our service providers may process data outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place:
- PayPal: Operates servers in the EU and US. Cross-border transfers are covered by PayPal's binding corporate rules and EU Standard Contractual Clauses (SCCs).
- Google / Firebase: May process data on servers in the US. Google participates in the EU-US Data Privacy Framework and uses SCCs for data transfers.
- Other Providers: Any other provider processing data outside the EEA is contractually required to implement SCCs or another approved transfer mechanism under GDPR Chapter V.
You may request information about the specific safeguards in place for international transfers by contacting us at support@auratech.store.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by law:
- Order and financial records: Retained for 7 years from the date of transaction, as required by Slovenian accounting law (ZGD-1) and EU VAT regulations
- Customer account data: Retained for as long as your account remains active. If you request account deletion, we will delete your account data within 30 days, subject to any legal retention requirements
- Support communications: Retained for 3 years to handle any follow-up queries, warranty claims, or legal disputes
- Marketing consent records: Retained until you withdraw consent, plus an additional period sufficient to demonstrate compliance
- Analytics data: Typically retained in anonymized/aggregated form indefinitely; raw data retained for up to 26 months
- Cookie data: As specified in our Cookie Policy
After the applicable retention period expires, data is securely deleted or anonymized.
8. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights in relation to your personal data:
- Right of Access (Art. 15): You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of it along with information about how it is used.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data we hold about you.
- Right to Erasure / "Right to be Forgotten" (Art. 17): You have the right to request deletion of your personal data where it is no longer necessary for the purposes it was collected, where you withdraw consent, or where we have no legitimate grounds to continue processing it. This right is subject to legal retention obligations.
- Right to Restriction of Processing (Art. 18): You have the right to request that we restrict the processing of your data in certain circumstances (e.g., while accuracy is being contested).
- Right to Data Portability (Art. 20): Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.
- Right to Object (Art. 21): You have the right to object at any time to processing of your personal data based on legitimate interests, including profiling. You also have an absolute right to object to processing for direct marketing purposes.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right Not to Be Subject to Automated Decision-Making (Art. 22): You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects on you. We do not currently use such automated decision-making for order processing.
9. How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us:
Email: support@auratech.store
Subject line: "GDPR Data Request – [Your Right]"
Include: Your full name, email address associated with your account, and a clear description of the right you wish to exercise
We will respond to all verified GDPR requests within 30 days of receipt. In complex cases, we may extend this period by a further 60 days, in which case we will notify you of the extension and the reasons for it.
We may need to verify your identity before processing your request to protect against unauthorized access to data. We will not charge a fee for reasonable requests; however, we may charge a reasonable administrative fee for manifestly unfounded or excessive requests.
If we are unable to fully satisfy your request (e.g., due to legal retention obligations), we will explain why.
10. Cookie Usage
Our website uses cookies — small text files stored on your device — to ensure essential functionality, remember your preferences, analyze usage patterns, and (with your consent) deliver relevant marketing.
We distinguish between:
- Essential cookies: Required for the website to function (e.g., shopping cart, session management). No consent required.
- Analytics cookies: Help us understand how visitors use our site. Require consent.
- Marketing cookies: Used for targeted advertising. Require consent.
For full details on the cookies we use, how to manage or withdraw cookie consent, and third-party cookie policies, please see our dedicated Cookie Policy.
11. Children's Privacy
Our website and services are intended for individuals aged 16 years or older. We do not knowingly collect, process, or store personal data from children under the age of 16 without verifiable parental or guardian consent.
In accordance with GDPR Article 8, where consent is the legal basis for processing and the individual is under 16, consent must be given or authorized by a parent or legal guardian.
If you believe a child under 16 has provided us with personal data without appropriate consent, please contact us immediately at support@auratech.store and we will take prompt steps to delete that information.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a notice on our website for a reasonable period
- If required by GDPR, seek fresh consent from you
We encourage you to review this Privacy Policy periodically. Your continued use of our website after any updates constitutes acknowledgment of the revised policy.
Previous versions of this Privacy Policy are available on request by contacting support@auratech.store.
13. Supervisory Authority & Complaints
If you believe your personal data is being processed in violation of the GDPR or applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority.
As a Slovenian-registered business, our lead supervisory authority is:
Information Commissioner of Slovenia (Informacijski pooblaščenec — IP-RS)
Website: https://www.ip-rs.si/
Address: Dunajska cesta 22, 1000 Ljubljana, Slovenia
Email: gp.ip@ip-rs.si
If you are located in another EU member state, you may also lodge a complaint with the data protection supervisory authority in your country of habitual residence or place of work.
We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority. Please contact us at support@auratech.store first.
14. Contact the Data Controller
For all privacy-related inquiries, data subject requests, or concerns about how we handle your personal data, please contact us:
Privacy Email: support@auratech.store
Data Controller: [YOUR_COMPANY_NAME]
Address: [YOUR_ADDRESS_SLOVENIA]
Response Time: We aim to respond to all privacy requests within 30 days
As a sole trader (s.p.), we are not required to appoint a Data Protection Officer (DPO) under GDPR Article 37 given our scale of operations. However, we take data protection seriously and are happy to address any concerns you may have.