Privacy Policy

Last updated: 19 July 2026

1. Data Controller

The controller of your personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the "GDPR") is:

BenoCode s.r.o.
Registered office: Rázusova 6, 949 01 Nitra, Slovak Republic
IČO: 55 920 918 — VAT: SK2122131110
Email: [email protected]
Phone: +421 910 610 892

We have not appointed a Data Protection Officer (DPO) as we are not required to do so under Article 37 GDPR. For all data-protection enquiries, please contact us using the details above.

2. Categories of Personal Data We Process

  • Identification and contact data: first name, last name, postal address, email address, telephone number.
  • Order and payment data: order content, order ID, payment method (we do not store full card numbers — these are handled by our payment processor), invoice information.
  • Communication data: emails, messages and other correspondence with us.
  • Technical data: IP address, browser type, device identifiers, pages visited, referrer URL, language preference, time of visit, cookie identifiers.
  • Marketing data: newsletter preferences, opt-in records, click and open statistics (only if you have opted in).

3. Purposes and Lawful Bases for Processing

PurposeLawful basis (GDPR Art. 6)Retention
Processing and fulfilling orders, customer support, returns/refundsPerformance of a contract — Art. 6(1)(b)For the duration of the contract + statutory periods
Issuing invoices, accounting, tax recordsLegal obligation — Art. 6(1)(c)10 years (Slovak Accounting Act)
Newsletter and marketing emailsConsent — Art. 6(1)(a)Until consent is withdrawn
Fraud prevention, IT security, and server-log diagnosticsLegitimate interest — Art. 6(1)(f)Up to 14 months
Strictly necessary cookies (session, cart, security)Necessary for the service — Art. 6(1)(b) / ePrivacyUp to 13 months
Defending or asserting legal claimsLegitimate interest — Art. 6(1)(f)Up to 4 years from contract conclusion

4. Recipients of Personal Data

In accordance with Article 13(1)(e) GDPR, we disclose the recipients (or categories of recipients) of your personal data below. We share personal data only to the extent necessary. Where these recipients process personal data on our behalf, they act as our processors under a data-processing agreement pursuant to Article 28 GDPR:

  • GoPay a.s. (Planá 67, 370 01 České Budějovice, Czech Republic) — payment gateway and payment processing (payment cards, Google Pay, Apple Pay). We do not store full payment-card numbers; these are processed by GoPay.
  • Sendinblue SAS, trading as Brevo (106 boulevard Haussmann, 75008 Paris, France) — sending of transactional emails (order confirmations, shipping notifications) and, only where you have opted in, newsletter emails.
  • Zásilkovna s.r.o. (Packeta / Zásielkovňa) (Lihovarská 1060/12, 190 00 Prague 9, Czech Republic) and Packeta group entities — delivery of parcels and shipment tracking.
  • Our hosting and infrastructure provider — the e-shop is self-hosted on the operator's own infrastructure located within the European Union (Slovakia) — operation of the servers on which the website and store run.
  • Accountants and tax advisors bound by professional secrecy.
  • Public authorities where required by law.

5. International Transfers

Your personal data are processed within the European Union / European Economic Area. The processors listed above are established in the EU (Slovakia, the Czech Republic and France). We do not routinely transfer your personal data to third countries outside the EEA. Should such a transfer become necessary in the future, it will take place only under an appropriate safeguard pursuant to Chapter V GDPR — such as a European Commission adequacy decision or Standard Contractual Clauses — and we will update this Privacy Policy accordingly. You may request copies of these safeguards by contacting us.

6. Cookies and Similar Technologies

Our website currently uses only a small number of essential and functional cookies. We do not run any analytics, advertising or third-party tracking cookies. You can find detailed information at any time using the "Cookie preferences" link in the footer. The cookies we use are:

  • Strictly necessary — required for the website to work, e.g. the shopping cart and your cookie-consent choice. Cannot be disabled.
  • Functional — remember your selected currency and language.

We do not currently set analytics or marketing cookies. Should we introduce them in the future, we will request your consent beforehand and update this Privacy Policy and our Cookie Preferences page.

7. Your Rights Under GDPR

Subject to the conditions of the GDPR you have the right to:

  • Access your personal data (Art. 15);
  • Rectification of inaccurate data (Art. 16);
  • Erasure ("right to be forgotten", Art. 17);
  • Restriction of processing (Art. 18);
  • Data portability (Art. 20);
  • Object to processing based on legitimate interest or for direct marketing (Art. 21);
  • Withdraw consent at any time, without affecting the lawfulness of processing performed before withdrawal (Art. 7(3));
  • Lodge a complaint with a supervisory authority (see section 8).

To exercise any of these rights, write to [email protected]. We will respond within one (1) month.

8. Right to Lodge a Complaint

The competent supervisory authority for our company is:

Úrad na ochranu osobných údajov Slovenskej republiky
(Office for Personal Data Protection of the Slovak Republic)
Hraničná 12, 820 07 Bratislava 27, Slovakia
Telephone: +421 2 32 31 32 14 — Email: [email protected]
Web: dataprotection.gov.sk

You may also lodge a complaint with the supervisory authority of the EU/EEA Member State where you reside.

9. Automated Decision-Making

We do not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

10. Children

The Store is intended for adults. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

11. Security

We implement appropriate technical and organisational measures to protect your personal data, including HTTPS encryption, role-based access controls, regular security reviews of our processors, and secure payment processing.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top indicates when the policy was last revised. Material changes will be notified prominently on the website.