Last updated: May 17, 2025
Welcome to our website! This Privacy Policy explains how Fotomedia, Mihael Laznik s.p. (hereinafter "we", "us" or "our") collects, uses, discloses, and protects your personal data when you visit our website, use our services, subscribe to our newsletter, or otherwise communicate with us. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and the Personal Data Protection Act (ZVOP-2).
The controller of your personal data is:
Fotomedia, Mihael Laznik s.p.
Radvanjska cesta 43
2000 Maribor
Registration number: 9583700000
VAT number: SI 74192744
Contact phone number: 02 332 15 10
Email for privacy inquiries: press@fotomedia.si
For all questions regarding the processing of your personal data and the exercise of your rights, you can contact us directly using the contact details provided in section 1.
We collect the following types of personal data:
We process your personal data for the following purposes and on the following legal bases:
Providing our services / online store (e.g., order processing, delivery, customer support):**
*Types of data:* Name and surname, phone number, email address, delivery address, purchase data.
*Legal basis:* Performance of a contract to which you are a party (purchase of products/services), or to take steps at your request prior to entering into a contract (Article 6(1)(b) GDPR).
Website analytics:**
*Types of data:* IP address, website usage data, cookies.
*Legal basis:* Our legitimate interest in improving our website, services, and user experience (Article 6(1)(f) GDPR). We ensure that our legitimate interests do not override your interests or fundamental rights and freedoms. For certain analytical cookies, we will obtain your consent.
Newsletter subscription:**
*Types of data:* Email address, name and surname, phone number.
*Legal basis:* Your explicit consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
Responding to inquiries via contact form:**
*Types of data:* Name and surname, phone number, email address, content of your message.
*Legal basis:* Our legitimate interest in effectively communicating with customers and potential customers (Article 6(1)(f) GDPR) or taking steps at your request prior to potentially entering into a contract (Article 6(1)(b) GDPR), depending on the content of the inquiry.
Fulfilling legal obligations:**
*Types of data:* Data necessary for issuing invoices, keeping business records, etc.
*Legal basis:* Compliance with a legal obligation to which we are subject (e.g., tax legislation) (Article 6(1)(c) GDPR).
We do not sell, trade, or loan your personal data to third parties. We may share your data only with the following categories of recipients when it is strictly necessary to achieve the purposes described in this policy:
Service providers (processors):** For the operation of our website and the provision of services, we use external providers who may process your personal data on our behalf. This includes:
Google Analytics:** For website traffic analysis. Google Analytics uses cookies to collect anonymized information. More about how Google uses data can be found at: https://policies.google.com/technologies/partner-sites. Data may be transferred to the USA based on appropriate safeguards (e.g., Standard Contractual Clauses and possible additional measures, or if Google is certified under the Data Privacy Framework program).
Payment service providers:** For processing payments for our services, we use the following external providers: Stripe, Mollie, Paypal, and SumUp. These providers collect and process your personal data (such as payment card data, transaction data) directly for the purpose of executing the payment. Their privacy policies govern their use of your data, so we recommend that you review them.
Email service provider (newsletters):** For sending our newsletters and other commercial communications, we use Mailchimp. For this purpose, we provide Mailchimp with your email address and possibly your name, if you provided it when signing up. Mailchimp may transfer and process data in the USA; to ensure an adequate level of data protection, they rely on Standard Contractual Clauses and other mechanisms compliant with GDPR. More information can be found in their privacy policy.
Other providers:** Website hosting provider, accounting service. We have appropriate data processing agreements with these providers, ensuring that they process your data only according to our instructions and in compliance with applicable data protection legislation.
Government authorities:** In cases where required by applicable law (e.g., at the request of a court, tax authorities), we may disclose your personal data to the competent government authorities.
When using Google Analytics, data may be transferred to the United States of America. Google commits to complying with appropriate data transfer mechanisms, such as Standard Contractual Clauses (SCC) and/or certification under the EU-US Data Privacy Framework, which ensures an adequate level of data protection. We will provide more details about this in our cookie policy. If in the future there would be a transfer of data to other third countries, we will ensure that such transfer is carried out only with appropriate safeguards as determined by the GDPR (e.g., adequacy decisions, standard contractual clauses, binding corporate rules).
We retain your personal data only for as long as necessary for the purposes for which they were collected, or as required by applicable regulations:
Data for contract performance (orders):** We keep them for the duration of the contractual relationship and for an additional [e.g., 5 years] after termination in accordance with limitation periods. We keep invoices for 10 years in accordance with tax legislation.
Data collected based on consent (e.g., for newsletters):** We keep them until you withdraw your consent.
Analytical data (e.g., via Google Analytics):** They are typically stored for a shorter period, e.g., [26 months], or as specified in the service settings and our cookie policy. Anonymized data may be stored longer.
Data from contact forms:** We keep them for as long as necessary to resolve your inquiry, and then for a short period for record-keeping purposes, unless longer retention is necessary due to another legal basis.
After the retention period expires, we effectively and permanently delete or anonymize personal data so that it can no longer be linked to you.
Regarding your personal data, you have the following rights:
Right of access:** You have the right to request information about whether we process your personal data, and if so, access to that data and certain information about the processing (purpose, types of data, recipients, retention period, data sources, existence of automated decision-making, information about transfers to third countries).
Right to rectification:** You have the right to have inaccurate personal data concerning you rectified without undue delay. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed.
Right to erasure ('right to be forgotten'):** You have the right to obtain the erasure of your personal data without undue delay where there are valid grounds for this (e.g., the data are no longer necessary for the purposes for which they were collected, withdrawal of consent and no other legal basis, objection to processing and no overriding legitimate grounds, unlawful processing, etc.).
Right to restriction of processing:** You have the right to obtain restriction of processing of your personal data in certain cases (e.g., if you contest the accuracy of the data, if the processing is unlawful and you oppose erasure, if we no longer need the data but you need them for the establishment, exercise or defense of legal claims, or if you have objected to processing).
Right to data portability:** You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and the right to transmit those data to another controller without hindrance from us, where the processing is based on consent or a contract and is carried out by automated means.
Right to object:** When we process your data based on legitimate interests for direct marketing purposes, you have the right to object at any time to such processing. When we process your data based on legitimate interests for other purposes, you have the right to object to such processing on grounds relating to your particular situation; in this case, we will cease processing the data, unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defense of legal claims.
Right to withdraw consent:** Where the processing of your personal data is based on your consent, you have the right to withdraw that consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
You can exercise your rights by sending a written request to the email address press@fotomedia.si or by mail to the address listed in section 1. We will respond to your request in accordance with applicable law, usually within one month of receiving the request. This period may be extended by up to two additional months if necessary, taking into account the complexity and number of requests.
Our website uses cookies to provide a better user experience, analyze usage, and potentially for targeted advertising. Cookies are small text files that the website stores on your device.
We use the following types of cookies:
Necessary cookies:** These cookies are required for the website to function and cannot be turned off. They are usually only set in response to actions you take, such as setting privacy preferences, logging in, or filling out forms. Your consent is not required for these cookies.
Analytical/statistical cookies:** These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our website (e.g., Google Analytics). They help us determine which pages are more or less popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. We will obtain your consent before placing these cookies.
Functional cookies:** These cookies enable the website to provide enhanced functionality and personalization. We will obtain your consent before placing these cookies.
Marketing cookies:** These cookies may be set through our website by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant advertisements on other websites. We will obtain your consent before placing these cookies.
When you first visit our website, we will ask for your consent to place non-essential cookies through a cookie banner. You can change your cookie settings or withdraw your consent at any time through our cookie policy. More detailed information about the cookies we use, their purposes, duration, and how to manage them is available in our Cookie Policy.
We are committed to ensuring the security of your personal data. We have implemented appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures include [briefly describe measures, e.g., use of SSL encryption, regular software updates, limited access to data, backups, etc.]. However, no data transmission over the internet or storage system is 100% secure.
Newsletter subscription:** If you subscribe to our newsletter, we will use your email address to send news, offers, and other information about our products and services. We do this based on your explicit consent. You can unsubscribe from receiving newsletters at any time by clicking on the unsubscribe link in each email received or by contacting us.
Contact forms:** When you contact us through the contact form on our website, we will use the collected data (name and surname, phone number, email address, message content) exclusively to respond to your inquiry or resolve your request.
If you believe that the processing of your personal data violates the provisions of the GDPR or ZVOP-2, you have the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia.
Contact details of the supervisory authority:
Information Commissioner
Dunajska cesta 22
1000 Ljubljana
Slovenia
Email: gp.ip@ip-rs.si
Phone: 01 230 97 30
Website: www.ip-rs.si
However, we recommend that you first try to resolve the matter directly with us before filing a complaint.
We may occasionally update this Privacy Policy to reflect changes in our data processing practices or changes in applicable legislation. Any changes will be posted on this website with the date of the last update. We recommend that you regularly review this policy to stay informed of any changes. In the case of significant changes, we may also notify you in another appropriate way (e.g., via email or a notice on the website).
If you have any questions or concerns about this Privacy Policy or our processing of your personal data, please contact us at:
Fotomedia, Mihael Laznik s.p.
Radvanjska cesta 43, 2000 Maribor
Email: press@fotomedia.si