PRIVACY POLICY AND COOKIE NOTICE
Privacy Policy and Information provided by the Controller to the Data Subject when obtaining personal data from the Data Subject, including the Cookie Notice for the Online Store www.savon.sk
I. Controller
1.1. Identity and Contact Details of the Controller
Business Name: SAVON care s.r.o.
Registered Office: Šancová 5815/6, 902 01 Pezinok, Slovakia
Registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert No. 197241/B, Trade Register No. 130-31659.
Company ID: 53503915
Tax ID: 2122782992
VAT ID: SK2122782992
Bank Account: SK92 8330 0000 0029 0351 8643
The Seller is a VAT payer.
1.2. Contact Details of the Controller
E-mail: info@savon.sk
Phone: +421 903 113 671
1.3. Postal Address of the Controller
SAVON care s.r.o.902 01 Pezinok
Slovakia
1.4.
In accordance with Article 13(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), as well as Act No. 18/2018 Coll. on Personal Data Protection and Act No. 452/2021 Coll. on Electronic Communications, the Controller hereby provides the Data Subject (Customer), from whom the Controller (Seller) obtains personal data, with the following information, instructions and explanations.
II. References
2.1.
This Privacy Policy and Information Notice forms an integral part of the General Terms and Conditions published on the Seller’s Website.
2.2.
The Merchant informs consumers that there are no specific codes of conduct to which the Seller has committed. A code of conduct means an agreement or set of rules defining the Seller’s behaviour in relation to one or more specific commercial practices or business sectors, provided that such obligations are not already established by law, other legal regulations or decisions of public authorities.
III. Retention Period
3.1.
The Controller stores the Data Subject’s personal data only for the period necessary to fulfil contractual obligations and for subsequent archiving in accordance with statutory retention periods.
Where the Data Subject has consented to receiving marketing e-mails and similar offers, personal data will be processed for these purposes until such consent is withdrawn by the Data Subject, but for no longer than 10 years.
IV. Processed Personal Data
4.1.
The Controller processes the following personal data:
-
First name
-
Last name
-
Residential address
-
E-mail address
-
Landline telephone number
-
Mobile telephone number
-
Billing address
-
Delivery address
-
Data obtained through cookies
-
IP address
V. Contact Details of the Data Protection Officer
5.1.
The Controller has not appointed a Data Protection Officer pursuant to Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
5.2.
The Controller is also the Seller within the meaning defined in the General Terms and Conditions of this website.
VI. Purposes of Processing the Data Subject’s Personal Data and Retention Period
6.1. The purposes of processing the Data Subject’s personal data are mainly:
6.1.1. Records, creation and processing of contracts and client data for the purpose of concluding contracts with third parties.
6.1.2. Processing of accounting documents and documents related to the Controller’s business activities.
6.1.3. Compliance with legal obligations related to the archiving of documents, for example under Act No. 431/2002 Coll. on Accounting, as amended, and other applicable legal regulations.
6.1.4. Activities of the Controller related to fulfilling the Data Subject’s request, order, contract or similar arrangements.
6.1.5. Newsletter, marketing and similar advertising activities of the Controller, provided that the Data Subject has given consent to such marketing and advertising activities.
VII. Legal Basis for Processing the Data Subject’s Personal Data
7.1. If the Controller processes personal data on the basis of the Data Subject’s consent, such processing will begin only after the Data Subject has granted the relevant consent.
7.2. If the Controller processes the Data Subject’s personal data for the purpose of pre-contractual negotiations, conclusion and performance of a purchase contract, including the related delivery of goods, products or services, the Data Subject is obliged to provide the personal data necessary for the proper performance of the purchase contract. Otherwise, performance cannot be ensured. Personal data for this purpose are processed without the Data Subject’s consent.
VIII. Recipients or Categories of Recipients of Personal Data
8.1. The recipients of the Data Subject’s personal data will be, or may at least include:
8.1.1. Statutory bodies or members of the Controller’s statutory bodies.
8.1.2. Persons performing work for the Controller under employment or similar relationships.
8.1.3. Business representatives of the Controller and other persons cooperating with the Controller in fulfilling the Controller’s tasks. For the purposes of this document, employees of the Controller shall include all natural persons performing dependent work for the Controller under an employment contract or agreements on work performed outside employment.
8.1.4. The recipients of the Data Subject’s personal data will also include the Controller’s collaborators, business partners, suppliers and contractual partners, in particular: accounting companies, companies providing services related to software development and maintenance, companies providing legal services, consulting companies, companies ensuring transport and delivery of products to buyers and third parties, marketing companies, social network operators, payment gateway providers and other payment method providers.
8.1.5. Recipients of personal data may also include courts, law enforcement authorities, tax authorities and other state authorities where required by law. Personal data will be provided to such authorities and state institutions on the basis of and in accordance with the legal regulations of the Slovak Republic.
8.1.6. List of Third-Party Processors and Recipients Processing the Data Subject’s Personal Data:
General Logistics Systems Slovakia s.r.o., Budča 1039, 962 33 Budča, Slovak Republic – third party providing transportation services.
Packeta Slovakia s. r. o., Sliačska 1E, 831 02 Bratislava – Nové Mesto, Slovakia, Company ID: 48136999 – third party providing transportation services.
Slovak Parcel Service s.r.o., Senecká cesta 1, 900 28 Ivanka pri Dunaji, Slovakia, Company ID: 31329217 – third party providing transportation services.
Comgate a.s., Aupark, Gočárova třída 1754/48b, 500 02 Hradec Králové, Czech Republic, Company ID: 27924505 – third party providing the COMGATE payment gateway.
Shoptet, a.s., Dvořeckého 628/8, 169 00 Prague 6, Czech Republic, Company ID: 28935675, VAT ID: CZ28935675 – third party providing e-commerce platform and payment-related services.
REIA, s.r.o., Harmónia 1868, 900 01 Modra, Slovakia – third party providing accounting services.
Leadhub s.r.o., Jilmová 1456/75, Žižkov, 130 00 Prague 3, Czech Republic, Company ID: 04466683 – third party providing newsletter distribution services.
Heureka Shopping s.r.o., Karolinská 650/1, 186 00 Prague 8 – Karlín, Czech Republic, Company ID: 02387727 – third party providing customer satisfaction monitoring and the “Verified by Customers” service.
8.2. The Controller evaluates customer satisfaction through e-mail questionnaires within the Verified by Customers programme, in which the Controller’s online store participates.
The Controller sends such questionnaires to the Data Subject – Customer after each purchase made through the Controller’s online store, unless the Data Subject – Customer has objected to receiving electronic mail for direct marketing purposes in accordance with Act No. 452/2021 Coll., as amended.
The processing of personal data for the purpose of sending questionnaires within the Verified by Customers programme is carried out on the basis of the Controller’s legitimate interest, consisting of measuring customer satisfaction with purchases made through the Seller’s online store.
For the purpose of sending questionnaires, evaluating customer feedback and analysing market position, the Controller uses a data processor, namely the operator of the Heureka.sk portal. For these purposes, the Controller may provide information about the purchased goods and the Customer’s e-mail address.
The Customer’s personal data are not transferred to any third party for their own independent purposes when e-mail questionnaires are sent.
The Customer may object to receiving questionnaires within the Verified by Customers programme at any time by using the unsubscribe link included in the questionnaire e-mail. If the Customer objects, the Controller will no longer send such questionnaires.
IX. Information on Transfers of Personal Data to Third Countries and Data Retention
9.1. Applicable. The Controller transfers personal data in the form of cookies to third countries through the following entities:
Google Pixels
Google HQ
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA
Further information on privacy protection is available at:
https://support.google.com/analytics/topic/2919631?hl=en
Meta Pixels
Meta Platforms Ireland Limited
4 Grand Canal Square
Grand Canal Harbour
Dublin 2
Ireland
Further information on privacy protection is available at:
https://www.facebook.com/privacy/policy/
X. Information on the Rights of the Data Subject
10.1. The Data Subject has, among others, the following rights:
10.1.1. The rights listed in Section 10.1 do not affect any other rights of the Data Subject provided under applicable legislation.
10.1.2. Right of Access to Personal Data (Article 15 GDPR)
The Data Subject has the right to obtain from the Controller confirmation as to whether or not personal data concerning them are being processed and, where that is the case, access to those personal data.
The Data Subject also has the right to obtain information regarding:
-
the purposes of processing,
-
the categories of personal data concerned,
-
the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations,
-
the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period,
-
the existence of the right to request rectification or erasure of personal data or restriction of processing concerning the Data Subject,
-
the right to object to such processing,
-
the right to lodge a complaint with a supervisory authority,
-
where the personal data are not collected from the Data Subject, any available information as to their source,
-
the existence of automated decision-making, including profiling referred to in Article 22(1) and (4) GDPR, and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the Data Subject,
-
the appropriate safeguards pursuant to Article 46 GDPR where personal data are transferred to a third country or an international organisation.
10.1.3. Right to Obtain a Copy of Personal Data
The Data Subject has the right to obtain a copy of the personal data being processed, provided that the exercise of this right does not adversely affect the rights and freedoms of others.
10.1.4. Right to Rectification (Article 16 GDPR)
The Data Subject has the right to have inaccurate personal data concerning them corrected by the Controller without undue delay.
The Data Subject also has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
10.1.5. Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)
The Data Subject has the right to obtain from the Controller the erasure of personal data concerning them without undue delay where one of the following grounds applies:
-
the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed,
-
the Data Subject withdraws consent on which the processing is based and there is no other legal ground for the processing,
-
the Data Subject objects to processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for processing,
-
the Data Subject objects to processing pursuant to Article 21(2) GDPR,
-
the personal data have been unlawfully processed,
-
the personal data must be erased for compliance with a legal obligation under European Union or Member State law,
-
the personal data were collected in relation to the offer of information society services referred to in Article 8(1) GDPR.
10.1.6.
Where the Controller has made the personal data public and is obliged to erase them, the Controller shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers processing the personal data that the Data Subject has requested the erasure of any links to, or copies or replications of, those personal data.
10.1.7.
The right to erasure shall not apply where processing is necessary for exercising the right of freedom of expression and information.
10.1.8.
The right to erasure shall also not apply where processing is necessary for compliance with a legal obligation under European Union or Member State law to which the Controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller.
10.1.9.
The right to erasure shall not apply where processing is necessary for reasons of public interest in the area of public health in accordance with Article 9(2)(h) and (i) GDPR and Article 9(3) GDPR.
10.1.10.
The right to erasure shall not apply where processing is necessary for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes pursuant to Article 89(1) GDPR, insofar as the right referred to in Article 17(1) GDPR is likely to render impossible or seriously impair the achievement of the objectives of that processing, or for the establishment, exercise or defence of legal claims.
10.1.11. Right to Restriction of Processing (Article 18 GDPR)
The Data Subject has the right to obtain from the Controller restriction of processing.
10.1.12.
The Controller shall restrict processing where one of the following applies:
-
the accuracy of the personal data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the personal data,
-
the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead,
-
the Controller no longer needs the personal data for processing purposes, but they are required by the Data Subject for the establishment, exercise or defence of legal claims,
-
the Data Subject has objected to processing pursuant to Article 21(1) GDPR pending verification whether the legitimate grounds of the Controller override those of the Data Subject.
10.1.13.
Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the Data Subject’s consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.
10.1.14. The Data Subject has the right to be informed in advance of the lifting of any restriction on the processing of personal data.
10.1.15. Right to Notification Regarding Recipients (Article 19 GDPR)
The Data Subject has the right to require that the Controller communicate any rectification or erasure of personal data or restriction of processing carried out pursuant to Article 16, Article 17(1), and Article 18 GDPR to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
The Data Subject also has the right to be informed by the Controller about those recipients if requested.
10.1.16. Right to Data Portability (Article 20 GDPR)
The Data Subject has the right to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the Controller, where:
a) the processing is based on the Data Subject’s consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, or on a contract pursuant to Article 6(1)(b) GDPR; and
b) the processing is carried out by automated means.
10.1.17.
The right to receive personal data in a structured, commonly used and machine-readable format and to transmit those data to another controller shall apply only where such transmission does not adversely affect the rights and freedoms of others.
10.1.18.
The Data Subject has the right to have personal data transmitted directly from one controller to another, where technically feasible.
10.1.19. Right to Object (Article 21 GDPR)
The Data Subject has the following rights regarding objections to processing:
10.1.20.
The Data Subject has the right to object at any time, on grounds relating to their particular situation, to processing of personal data concerning them based on Article 6(1)(e) or Article 6(1)(f) GDPR, including profiling based on those provisions.
10.1.21.
Where the Data Subject exercises the right to object under Article 21 GDPR, the Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or for the establishment, exercise or defence of legal claims.
10.1.22.
The Data Subject has the right to object at any time to the processing of personal data concerning them for direct marketing purposes, including profiling insofar as it is related to such direct marketing.
Where the Data Subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
10.1.23.
In connection with the use of information society services, the Data Subject has the right to exercise the right to object by automated means using technical specifications.
10.1.24.
The Data Subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) GDPR, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
10.1.25. Rights Related to Automated Individual Decision-Making (Article 22 GDPR)
The Data Subject has the following rights in relation to automated decision-making:
10.1.26.
The Data Subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, except in cases provided for in Article 22(2) GDPR, namely where the decision:
a) is necessary for entering into, or performance of, a contract between the Data Subject and the Controller;
10.1.27.
b) is authorised by European Union law or the law of a Member State to which the Controller is subject and which also lays down suitable measures to safeguard the Data Subject’s rights, freedoms and legitimate interests; or
c) is based on the Data Subject’s explicit consent.
XI. Information on the Data Subject’s Right to Withdraw Consent to the Processing of Personal Data
11.1. The Data Subject is entitled to withdraw their consent to the processing of personal data at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
The Data Subject may withdraw their consent to the processing of personal data at any time, either in full or in part.
A partial withdrawal of consent may relate to a specific processing operation or several processing operations, while the lawfulness of the processing of personal data for the remaining processing operations shall remain unaffected.
A partial withdrawal of consent may also relate to a specific purpose or several specific purposes of personal data processing, while the lawfulness of processing for other purposes shall remain unaffected.
The Data Subject may exercise the right to withdraw consent:
-
in writing, by sending a notice to the Controller’s address registered as its official business address at the time of withdrawal; or
-
electronically, by sending an e-mail to the Controller’s e-mail address specified in the Controller Identification section of this document.
XII. Information on the Data Subject’s Right to Lodge a Complaint with a Supervisory Authority
12.1. The Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if the Data Subject considers that the processing of personal data relating to them infringes the GDPR.
This right applies without prejudice to any other administrative or judicial remedy.
The Data Subject also has the right to be informed by the supervisory authority to which the complaint has been submitted about the progress and outcome of the complaint, including the possibility of seeking a judicial remedy under Article 78 GDPR.
12.2. The supervisory authority in the Slovak Republic is:
Office for Personal Data Protection of the Slovak Republic
Park One Building
Námestie 1. mája 18
811 06 Bratislava
Slovak Republic
Telephone: +421 2 32 31 32 14
E-mail: statny.dozor@pdp.gov.sk
XIII. Information Related to Automated Decision-Making, Including Profiling
13.1. As the Controller does not process the Data Subject’s personal data by means of automated individual decision-making, including profiling as referred to in Article 22(1) and Article 22(4) GDPR, the Controller is not required to provide the information specified in Article 13(2)(f) GDPR, namely information concerning:
-
automated decision-making, including profiling,
-
the logic involved,
-
and the significance and envisaged consequences of such processing for the Data Subject.
Not applicable.
XIV. Personal Data Protection and Use of Cookies. Information and Explanation of Cookies, Scripts and Pixels
14.1.
The Website Operator provides the following brief explanation of the functions of cookies, scripts and pixels:
14.1.1.
Cookies are text files containing a small amount of information that are downloaded to your device when you visit a website. Through these files, the website remembers information about your actions and preferences (such as login details, language, font size and other display settings) for a certain period of time, so that you do not have to re-enter them when you revisit the website or browse its individual pages.
A script is a piece of program code used to ensure the proper and interactive functioning of a website. This code is executed either on the Operator’s server or on your device.
A pixel is a small invisible text or image placed on a website and used to monitor website traffic. In order to do so, various data are collected and stored through pixels.
14.1.2. Types of Cookies
Necessary Cookies
These cookies ensure the proper functioning and usability of the Operator’s website. These cookies are used without requiring consent.
Functional Cookies
These cookies relate to users’ preferences concerning the use of cookies on the website, including options to accept, reject or customize cookie settings according to privacy preferences.
Statistical Cookies
These cookies enable the Operator to obtain statistics regarding the use of its website. These cookies are used only with the user’s consent.
Advertising Cookies
These cookies are used to create advertising profiles and for similar marketing activities. These cookies are used only with the user’s consent.
14.2. How to Control Cookies
14.2.1.
You can control and/or delete cookies as you wish. More information can be found at aboutcookies.org.
You can delete all cookies already stored on your computer or other device, and most web browsers can be configured to prevent them from being stored.
14.3.1. Cookies Used
Necessary Cookies
PHPSESSID
First-party cookie generated by PHP-based applications. It is a general-purpose identifier used to maintain user session variables. Usually, it is a randomly generated number. Its specific use depends on the website, but a common example is maintaining a user’s logged-in status across pages.
_lhic
First-party cookie, retention period: 1 year and 1 month. This cookie is used for website identification and session management purposes.
Functional Cookies
currencyCode
First-party cookie, retention period: 59 minutes and 59 seconds. This cookie remembers the user’s selected currency for displaying prices and carrying out transactions in the chosen currency.
language
First-party cookie, retention period: 11 months and 4 weeks. This cookie is generally used to store language preferences and display content in the selected language.
Statistical Cookies
_ga
First-party cookie, retention period: 1 year and 1 month. Associated with Google Universal Analytics. It distinguishes unique users by assigning a randomly generated number as a client identifier and is used to calculate visitor, session and campaign statistics.
_gid
First-party cookie, retention period: 1 day. Set by Google Analytics. It stores and updates a unique value for each visited page and is used to count and track page views.
_ga_D53LQK3BW5
First-party cookie, retention period: 1 year and 1 month. Used by Google Analytics to maintain session state.
_ga_NMEQ6F57RP
First-party cookie, retention period: 1 year and 1 month. Used by Google Analytics to maintain session state.
Advertising Cookies
MUID
Third-party cookie, retention period: 1 year and 3 weeks. Commonly used by Microsoft as a unique user identifier. It may be set by embedded Microsoft scripts and is generally synchronized across Microsoft domains to enable user tracking.
_fbp
First-party cookie, retention period: 3 months. Used by Meta to provide advertising products, such as real-time bidding from third-party advertisers.
_gcl_au
First-party cookie, retention period: 3 months. Used by Google AdSense to experiment with advertising efficiency on websites using its services.
_uetsid
First-party cookie, retention period: 1 day. Used by Microsoft Bing to determine which advertisements should be displayed and which may be relevant to the end user viewing the website.
_gat_gtag_UA_189324564_1
First-party cookie, retention period: 53 seconds. Part of Google Analytics and used to limit the rate of requests.
_uetvid
First-party cookie, retention period: 1 year and 3 weeks. Used by Microsoft Bing Ads as a tracking cookie that enables interaction with users who have previously visited the website.
14.3.2. Cookies and Technologies Provided by Third Parties
Google HQ
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA
Further privacy information:
https://support.google.com/analytics/topic/2919631
Meta Pixels
Meta Platforms Ireland Limited
4 Grand Canal Square
Grand Canal Harbour
Dublin 2
Ireland
Further privacy information:
https://www.facebook.com/about/privacy/
Heureka Shopping s.r.o.
Karolinská 650/1
186 00 Prague 8 – Karlín
Czech Republic
Company ID: 02387727
Privacy Policy:
https://heureka.group/sk-sk/podmienky-pouzivania/ochrana-osobnych-udajov-na-portali-heureka-group-a-s/
XV. Final Provisions
15.1.
These Privacy Policy and Cookie Notice provisions form an integral part of the General Terms and Conditions and the Complaints Procedure.
The documents General Terms and Conditions and Complaints Procedure are published on the Seller’s Website.
15.2.
These Privacy Policy provisions become valid and effective upon their publication on the Seller’s Website on 04 February 2026.
This online store is certified by:
