GDPR Data Protection Information
Last updated: 2026
This Data Protection Information explains how Sport group d.o.o. (“Company”, “we”, “us”, or “our”) processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1. Data Controller
2. Categories of Personal Data
We may process the following categories of personal data:
- Identification data (name and surname)
- Contact data (email address, phone number)
- Address data (billing and shipping address)
- Transaction data (orders, purchases, invoices)
- Payment-related data (processed via secure third-party providers)
- Technical data (IP address, browser type, device information)
- Usage data (website interactions and analytics data)
3. Purpose of Processing
Your personal data is processed for the following purposes:
- Order processing and delivery
- Customer support and communication
- Payment processing and invoicing
- Compliance with legal obligations (tax and accounting)
- Fraud prevention and security
- Improvement of our website and services
- Marketing communications (only where consent is given)
4. Legal Basis for Processing
We process personal data based on the following legal grounds:
- Performance of a contract (Article 6(1)(b) GDPR)
- Compliance with legal obligations (Article 6(1)(c) GDPR)
- Legitimate interests (Article 6(1)(f) GDPR), such as improving services and preventing fraud
- Consent (Article 6(1)(a) GDPR), particularly for marketing
5. Data Recipients
Personal data may be shared with the following categories of recipients:
- Payment service providers
- Shipping and logistics partners
- IT and hosting providers
- Analytics and marketing service providers
All recipients process personal data only as necessary and in accordance with GDPR requirements.
6. Data Retention
Personal data is retained only for as long as necessary to:
- Fulfill contractual obligations
- Comply with legal requirements (e.g. accounting and tax laws)
- Resolve disputes and enforce agreements
7. Data Transfers
If personal data is transferred outside the European Economic Area (EEA), appropriate safeguards are implemented, such as Standard Contractual Clauses approved by the European Commission.
8. Your Rights
Under GDPR, you have the following rights:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Right to withdraw consent at any time (Article 7)
9. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
In Slovenia, the competent authority is:
Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec)
Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec)
10. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or disclosure.
11. Changes to This Information
We may update this Data Protection Information from time to time. The latest version will always be available on our website.
If you want, I can also tailor this specifically for: