Privacy Policy
1. Introduction and Controller Details
We appreciate your interest in our website. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website, contact us, create an account, place an order, request a withdrawal from a contract, or otherwise use our services.
The controller responsible for processing personal data on this website within the meaning of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) is:
Hifi Electronics s. r. o.
Jarabinková 6B
821 09 Bratislava
Slovakia
Company Registration No. (IČO): 57636419
Tax ID (DIČ): 2122861807
VAT ID: SK2122861807
Phone: +421 944 377 161
Email: ssbhifi@gmail.com
Hifi Electronics s. r. o. is registered in the Commercial Register of the Municipal Court Bratislava III, Section: Sro, File No.: 199668/B.
2. Data Collected When You Visit Our Website
When you use our website without registering or actively submitting information, our web server may automatically process technical data transmitted by your browser. This may include:
- The page or file requested
- Date and time of access
- Amount of data transferred
- Referring website or source
- Browser type and version
- Operating system
- IP address, where possible in shortened or anonymised form
- HTTP status and similar technical diagnostic information
This processing is carried out on the basis of our legitimate interests under Art. 6(1)(f) GDPR in operating a secure, stable, and functional website, detecting technical errors, and preventing misuse. Server log data may be reviewed where there are specific indications of unlawful use or a security incident.
Our website uses SSL/TLS encryption to protect personal data and confidential content transmitted through the website. An encrypted connection can normally be identified by “https://” and the lock symbol in the browser address bar.
3. Hosting and Content Delivery
We use hosting and technical infrastructure providers to make this website available. These providers may process website content, server logs, IP addresses, and technical connection data on our behalf. Processing is based on Art. 6(1)(f) GDPR and, where a provider acts as our processor, on a data processing agreement under Art. 28 GDPR.
Where service providers process data outside the European Economic Area, we use an applicable transfer mechanism, such as an adequacy decision or standard contractual clauses, where required by law.
4. Cookies and Consent Management
Our website uses cookies and similar technologies. Cookies are small text files stored on your device. Some cookies are technically necessary for the operation of the website, shopping cart, checkout, security, language selection, or account functions. Other cookies may be used for analytics or additional services only after consent has been given.
Necessary cookies are processed on the basis of Art. 6(1)(b) GDPR where required to provide a service requested by you, or Art. 6(1)(f) GDPR based on our legitimate interest in providing a secure and functional website. Non-essential cookies are used on the basis of your consent under Art. 6(1)(a) GDPR.
You may manage or withdraw your consent through the cookie settings available on our website. You may also configure your browser to reject or delete cookies. Disabling necessary cookies may restrict website functions.
5. Contact Requests and WPForms
When you contact us by email or through a form provided on our website, including forms created with WPForms, we process the information you provide, such as your name, email address, order number, message, and any other information entered into the form.
The legal basis is Art. 6(1)(b) GDPR where the communication relates to a contract, an order, pre-contractual measures, a warranty request, a return, or withdrawal from a contract. For general enquiries, processing is based on our legitimate interest in responding efficiently under Art. 6(1)(f) GDPR.
Form entries may also include technical metadata such as the date and time of submission, IP address, and browser information where required for security, spam prevention, or troubleshooting. Data is deleted when the matter has been finally resolved, unless statutory retention obligations or legal claims require longer storage.
6. Customer Accounts, Orders, and Contract Processing
When you create a customer account or place an order, we process data required to conclude and perform the contract. This may include:
- Name and company name
- Billing and delivery address
- Email address and telephone number
- Order details, products, quantities, prices, and currency
- Payment method and payment status
- VAT identification number where provided
- Shipping and tracking information
- Customer communications, withdrawal requests, returns, complaints, and warranty information
Processing is based on Art. 6(1)(b) GDPR for contract performance and pre-contractual measures. Data required for accounting, tax, customs, product compliance, or other statutory obligations is also processed under Art. 6(1)(c) GDPR.
Where products include digital elements or require safety, service, or update notices, we may use your contact details to provide legally required information. The legal basis is Art. 6(1)(c) GDPR or, where applicable, Art. 6(1)(b) GDPR.
7. Payments
Depending on the payment methods offered at checkout, payment data may be processed by us and by the selected payment service provider. We do not normally receive complete payment card details. Payment providers process payment information in accordance with their own legal obligations and privacy notices.
Direct bank transfer
If you pay by direct bank transfer, we process payment reference information, payer details shown in the bank transaction, amount, date, and payment status. Processing is necessary for contract performance under Art. 6(1)(b) GDPR and for accounting obligations under Art. 6(1)(c) GDPR.
PayPal
If PayPal or a PayPal-based payment method is offered and selected, payment information is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. The legal basis for transmission is Art. 6(1)(b) GDPR. PayPal may process data for payment execution, fraud prevention, regulatory compliance, and, where applicable, credit assessment. Further information is available in PayPal’s privacy statement:
https://www.paypal.com/webapps/mpp/ua/privacy-full
Stripe, card payments, Apple Pay, and Google Pay
Where card payments or wallet payments are offered through Stripe, payment information may be processed by Stripe Payments Europe, Limited, Ireland, and related Stripe entities. Depending on the selected wallet, Apple or Google may also process payment-related data under their own privacy terms. The legal basis for transmission is Art. 6(1)(b) GDPR. Further information is available at:
https://stripe.com/privacy
https://policies.google.com/privacy
https://www.apple.com/legal/privacy/
Only payment methods actually enabled and displayed during checkout are available to customers.
8. Shipping and Delivery Providers
To deliver orders, we provide the selected carrier or postal operator with the information necessary for delivery, normally the recipient’s name, delivery address, and shipment details. Processing is based on Art. 6(1)(b) GDPR.
Where you have consented to shipment notifications or where such communication is necessary to perform the delivery, we may also provide your email address or telephone number to the carrier. The legal basis is Art. 6(1)(a) GDPR or, where necessary for the requested delivery service, Art. 6(1)(b) GDPR.
The specific carrier may vary according to destination, parcel type, availability, and the shipping method selected at checkout. Carriers process shipment data in accordance with their own legal obligations and privacy notices.
9. VAT Number Validation
Where a business customer provides a VAT identification number, we may validate that number using official or authorised databases, such as the EU VAT Information Exchange System (VIES), and process the submitted VAT number, company name, and address for verification and tax documentation. Processing is based on Art. 6(1)(c) GDPR where required by law and otherwise on Art. 6(1)(f) GDPR based on our legitimate interest in verifying business customer information and applying the correct tax treatment.
10. Google reCAPTCHA
Our website may use Google reCAPTCHA, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to distinguish human input from automated access and to protect forms from spam, fraud, and misuse.
reCAPTCHA may process technical and behavioural data, including IP address, browser information, device data, time spent on the page, and interaction patterns. The legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in protecting the website and its forms. Where consent is required for the relevant implementation, processing takes place only under Art. 6(1)(a) GDPR after consent.
Data may be transferred to Google entities or servers outside the European Economic Area subject to applicable transfer safeguards. Further information is available at:
https://policies.google.com/privacy
11. Google Analytics
Where enabled, this website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics may use cookies or similar technologies to analyse website usage, measure traffic, and generate aggregated reports.
Google Analytics is activated only on the basis of your consent under Art. 6(1)(a) GDPR. You may withdraw consent at any time through our cookie settings. Where available, we use privacy-enhancing settings such as IP-related controls and data retention limits.
Data may be processed by Google outside the European Economic Area subject to applicable transfer safeguards. Further information is available at:
https://policies.google.com/privacy
12. Email Delivery and WP Mail SMTP
Our website uses WP Mail SMTP or a comparable mail-delivery configuration to send transactional emails, contact-form messages, order confirmations, password-reset emails, and other service communications. Depending on the configured mail provider, message content, sender and recipient addresses, technical delivery information, and related metadata may be processed by an external email or SMTP service provider.
Processing is based on Art. 6(1)(b) GDPR where necessary for contract-related communications and on Art. 6(1)(f) GDPR based on our legitimate interest in reliable and secure email delivery. Where a provider acts as our processor, processing is governed by an agreement under Art. 28 GDPR.
13. Comments and Reviews
If comment or review functions are available and you submit content, we may process and publish the name or display name selected by you, the submitted content, rating, and submission time. We may also process your email address and IP address for verification, abuse prevention, moderation, and defence against unlawful content.
Processing is based on Art. 6(1)(b) GDPR where the submission forms part of a customer relationship and on Art. 6(1)(f) GDPR based on our legitimate interests in operating, moderating, and securing comment and review functions. We may reject or remove unlawful, misleading, abusive, irrelevant, or fraudulent content.
14. Recipients and Categories of Recipients
Personal data may be disclosed only where necessary and lawful, including to:
- Hosting, IT, security, maintenance, and email service providers
- Payment service providers and banks
- Postal operators, carriers, fulfilment partners, and customs intermediaries
- Accounting, tax, legal, and compliance advisers
- Public authorities, courts, customs, tax authorities, or law enforcement where legally required
- Official VAT and business verification services
Service providers receive only the data required for their tasks and process it under applicable data protection obligations.
15. International Data Transfers
Some service providers may process personal data outside the European Economic Area. In such cases, transfers take place only where an appropriate legal mechanism is available, such as an adequacy decision under Art. 45 GDPR, standard contractual clauses under Art. 46 GDPR, or another lawful derogation or safeguard.
16. Legal Retention Periods
We retain personal data only for as long as necessary for the relevant purpose and in accordance with applicable legal retention periods.
- Contract, order, invoice, accounting, tax, and customs data is retained for the period required by applicable Slovak and EU law.
- Contact and support correspondence is retained until the matter is resolved and, where appropriate, for the period necessary to establish, exercise, or defend legal claims.
- Data processed on the basis of consent is retained until consent is withdrawn, unless another legal basis permits continued processing.
- Server logs and security data are retained only for the period required for operation, troubleshooting, fraud prevention, and security.
- Customer account data is retained while the account remains active and thereafter where required by law or legitimate legal interests.
When the applicable purpose and retention period end, data is deleted or anonymised unless continued storage is legally required.
17. Your Rights under the GDPR
Subject to the conditions and limitations provided by law, you have the following rights:
- Right of access under Art. 15 GDPR
- Right to rectification under Art. 16 GDPR
- Right to erasure under Art. 17 GDPR
- Right to restriction of processing under Art. 18 GDPR
- Right to notification under Art. 19 GDPR
- Right to data portability under Art. 20 GDPR
- Right to object under Art. 21 GDPR
- Right to withdraw consent at any time under Art. 7(3) GDPR
- Right to lodge a complaint with a supervisory authority under Art. 77 GDPR
To exercise your rights, contact us at ssbhifi@gmail.com. We may request information necessary to verify your identity before responding.
18. Right to Object
Where we process personal data on the basis of legitimate interests under Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to such processing.
If you object, we will stop processing the affected data unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is required for the establishment, exercise, or defence of legal claims.
Where personal data is processed for direct marketing, you have the right to object at any time to processing for such marketing. Following an objection, we will no longer process your data for direct marketing purposes.
19. Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.
The supervisory authority responsible for data protection in Slovakia is:
Office for Personal Data Protection of the Slovak Republic
Galvaniho Business Centrum II
Galvaniho 7/B
821 04 Bratislava
Slovakia
Website: https://dataprotection.gov.sk/
20. Data Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encrypted connections, access restrictions, software updates, backups, authentication controls, and security monitoring where appropriate.
No internet transmission or storage system can be guaranteed to be completely secure. You are responsible for keeping your account credentials confidential and for notifying us promptly if you suspect unauthorised use.
21. Changes to This Privacy Policy
We may update this Privacy Policy where necessary to reflect changes to our website, services, service providers, legal requirements, or data processing activities. The version published on this website is the current version.
Last updated: 2 August 2026
